Cited 35 time in
An Efficient Hyperparameter Control Method for a Network Intrusion Detection System Based on Proximal Policy Optimization
| DC Field | Value | Language |
|---|---|---|
| dc.contributor.author | Han, Hyojoon | - |
| dc.contributor.author | Kim, Hyukho | - |
| dc.contributor.author | Kim, Yangwoo | - |
| dc.date.accessioned | 2023-04-27T13:41:04Z | - |
| dc.date.available | 2023-04-27T13:41:04Z | - |
| dc.date.issued | 2022-01 | - |
| dc.identifier.issn | 2073-8994 | - |
| dc.identifier.issn | 2073-8994 | - |
| dc.identifier.uri | https://scholarworks.dongguk.edu/handle/sw.dongguk/3789 | - |
| dc.description.abstract | The complexity of network intrusion detection systems (IDSs) is increasing due to the continuous increases in network traffic, various attacks and the ever-changing network environment. In addition, network traffic is asymmetric with few attack data, but the attack data are so complex that it is difficult to detect one. Many studies on improving intrusion detection performance using feature engineering have been conducted. These studies work well in the dataset environment; however, it is challenging to cope with a changing network environment. This paper proposes an intrusion detection hyperparameter control system (IDHCS) that controls and trains a deep neural network (DNN) feature extractor and k-means clustering module as a reinforcement learning model based on proximal policy optimization (PPO). An IDHCS controls the DNN feature extractor to extract the most valuable features in the network environment, and identifies intrusion through k-means clustering. Through iterative learning using the PPO-based reinforcement learning model, the system is optimized to improve performance automatically according to the network environment, where the IDHCS is used. Experiments were conducted to evaluate the system performance using the CICIDS2017 and UNSW-NB15 datasets. In CICIDS2017, an F1-score of 0.96552 was achieved and UNSW-NB15 achieved an F1-score of 0.94268. An experiment was conducted by merging the two datasets to build a more extensive and complex test environment. By merging datasets, the attack types in the experiment became more diverse and their patterns became more complex. An F1-score of 0.93567 was achieved in the merged dataset, indicating 97% to 99% performance compared with CICIDS2017 and UNSW-NB15. The results reveal that the proposed IDHCS improved the performance of the IDS by automating learning new types of attacks by managing intrusion detection features regardless of the network environment changes through continuous learning. | - |
| dc.format.extent | 15 | - |
| dc.language | 영어 | - |
| dc.language.iso | ENG | - |
| dc.publisher | MDPI | - |
| dc.title | An Efficient Hyperparameter Control Method for a Network Intrusion Detection System Based on Proximal Policy Optimization | - |
| dc.type | Article | - |
| dc.publisher.location | 스위스 | - |
| dc.identifier.doi | 10.3390/sym14010161 | - |
| dc.identifier.scopusid | 2-s2.0-85123120593 | - |
| dc.identifier.wosid | 000748107200001 | - |
| dc.identifier.bibliographicCitation | Symmetry, v.14, no.1, pp 1 - 15 | - |
| dc.citation.title | Symmetry | - |
| dc.citation.volume | 14 | - |
| dc.citation.number | 1 | - |
| dc.citation.startPage | 1 | - |
| dc.citation.endPage | 15 | - |
| dc.type.docType | Article | - |
| dc.description.isOpenAccess | Y | - |
| dc.description.journalRegisteredClass | scie | - |
| dc.description.journalRegisteredClass | scopus | - |
| dc.relation.journalResearchArea | Science & Technology - Other Topics | - |
| dc.relation.journalWebOfScienceCategory | Multidisciplinary Sciences | - |
| dc.subject.keywordPlus | STACKED SPARSE AUTOENCODER | - |
| dc.subject.keywordPlus | SVM | - |
| dc.subject.keywordAuthor | intrusion detection system (IDS) | - |
| dc.subject.keywordAuthor | reinforcement learning (RL) | - |
| dc.subject.keywordAuthor | proximal policy optimization (PPO) | - |
| dc.subject.keywordAuthor | deep learning (DL) | - |
| dc.subject.keywordAuthor | deep neural network (DNN) | - |
| dc.subject.keywordAuthor | k-means | - |
| dc.subject.keywordAuthor | CICIDS2017 | - |
| dc.subject.keywordAuthor | UNSW-NB15 | - |
| dc.subject.keywordAuthor | network security | - |
| dc.subject.keywordAuthor | feature extraction | - |
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.
30, Pildong-ro 1-gil, Jung-gu, Seoul, 04620, Republic of Korea+82-2-2260-3114
Copyright(c) 2023 DONGGUK UNIVERSITY. ALL RIGHTS RESERVED.
Certain data included herein are derived from the © Web of Science of Clarivate Analytics. All rights reserved.
You may not copy or re-distribute this material in whole or in part without the prior written consent of Clarivate Analytics.
