Skip to main content
QUICK REVIEW

[Paper Review] Shallow and Deep Networks Intrusion Detection System: A Taxonomy and Survey

Elike Hodo, Xavier Bellekens|arXiv (Cornell University)|Jan 9, 2017
Network Security and Intrusion DetectionComputer Science97 references211 citations
TL;DR

This paper provides a taxonomy and survey of intrusion detection systems using shallow and deep networks, emphasizing feature selection and the balance of false/true positives.

ABSTRACT

Intrusion detection has attracted a considerable interest from researchers and industries. The community, after many years of research, still faces the problem of building reliable and efficient IDS that are capable of handling large quantities of data, with changing patterns in real time situations. The work presented in this manuscript classifies intrusion detection systems (IDS). Moreover, a taxonomy and survey of shallow and deep networks intrusion detection systems is presented based on previous and current works. This taxonomy and survey reviews machine learning techniques and their performance in detecting anomalies. Feature selection which influences the effectiveness of machine learning (ML) IDS is discussed to explain the role of feature selection in the classification and training phase of ML IDS. Finally, a discussion of the false and true positive alarm rates is presented to help researchers model reliable and efficient machine learning based intrusion detection systems.

Motivation & Objective

  • Classify intrusion detection systems into shallow and deep network approaches.
  • Present a taxonomy and survey of existing ML-based IDS and their performance.
  • Discuss the role of feature selection in ML-based IDS training and classification.
  • Explain how false and true positive alarm rates influence reliable IDS design.

Proposed method

  • Construct a taxonomy of shallow and deep networks intrusion detection systems from prior and current work.
  • Review machine learning techniques used in IDS and their anomaly-detection performance.
  • Discuss feature selection as a key factor influencing classifier training and accuracy.
  • Provide discussion on alarm rate metrics (false/true positives) to guide reliable IDS design.

Experimental results

Research questions

  • RQ1What are the existing shallow and deep network approaches used for intrusion detection?
  • RQ2How do machine learning techniques perform in detecting anomalies within IDS?
  • RQ3What is the role of feature selection in improving ML-based IDS performance?
  • RQ4How can false and true positive alarm rates be modeled and interpreted for reliable IDS?

Key findings

  • The paper offers a taxonomy and survey of shallow and deep networks in intrusion detection systems.
  • It discusses the influence of feature selection on the effectiveness of ML-based IDS.
  • It provides discussion on false and true positive alarm rates to aid in modeling reliable IDS.
  • The study synthesizes both prior and current works to map ML techniques to IDS performance.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.