N-GAN: a novel anomaly-based network intrusion detection with generative adversarial networks

Auwal Sani Iliyasu*, Huifang Deng

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

40 Scopus citations

Abstract

Network intrusion detection is one of the popular cyber defense mechanisms, which entails detection of cyber threat at network layer level. Currently, research on network intrusion detection systems (IDS) are mostly based on supervised deep learning (DL) methods, which require large amount of data to generalize well. However, collecting sufficient malicious samples for training supervised DL methods is non-trivial, especially in the modern day constantly evolving landscape of cyber threat. Unsupervised methods mitigate this issue by completely modeling the benign data, thereby establishing a normality threshold, and then flagged any data instance above that threshold as an anomaly. However, these approaches sometimes lead to too many false alarm rates (FARs). We hypothesize that, the problem is due to lack of prior knowledge on the distribution of anomaly (malicious samples), and their focus on only preserving data regularity information. Thus, adding even a few malicious samples during training can significantly improve the quality of learned representations thereby improving their robustness against FARs. Therefore, in this paper we propose N-GAN, a novel network intrusion detection technique based on generative adversarial networks (GAN). Our approach incorporates a few malicious samples during training (weakly supervised), which enable it to learn good representations instead of learning data noises or uninteresting data objects due to lack of such prior knowledge. We evaluate our N-GAN approach on a publicly available intrusion detection dataset, and achieve detection rate that surpasses other reconstruction-based anomaly intrusion detection methods on the same datasets.

Original languageEnglish
Pages (from-to)3365-3375
Number of pages11
JournalInternational Journal of Information Technology (Singapore)
Volume14
Issue number7
DOIs
StatePublished - Dec 2022
Externally publishedYes

Bibliographical note

Publisher Copyright:
© 2022, The Author(s), under exclusive licence to Bharati Vidyapeeth's Institute of Computer Applications and Management.

Keywords

  • Deep learning
  • Generative adversarial networks
  • Intrusion detection
  • Network security

ASJC Scopus subject areas

  • Information Systems
  • Computer Science Applications
  • Computer Networks and Communications
  • Computational Theory and Mathematics
  • Artificial Intelligence
  • Applied Mathematics
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'N-GAN: a novel anomaly-based network intrusion detection with generative adversarial networks'. Together they form a unique fingerprint.

Cite this