Skip to main navigation Skip to search Skip to main content

Enhancing network intrusion detection systems: A real-time adaptive machine learning approach for adversarial packet-mutation mitigation

  • The University of Sydney

Research output: Book chapter/Published conference paperConference paperpeer-review

Abstract

Network Intrusion Detection Systems (NIDS) are increasingly vulnerable to sophisticated packet-mutation attacks that evade traditional detection methods. This paper presents a runtime adaptive machine-learning strategy to combat such adversarial attacks. We introduce an Adaptive Layered Mutation Algorithm (ALMA) for generating advanced adversarial examples and a runtime adaptive learning framework for realtime detection and response. Our approach integrates these components to create a robust, self-evolving NIDS. Experiments comparing various feature extractors and machine learning classifiers demonstrate that our adaptive approach achieves up to 98% detection accuracy, significantly improving the identification of mutated packets over static models. The integrated system rapidly adapts to new attack patterns, achieving over 90% detection accuracy for novel attacks within 2-3 update cycles. This research contributes to network security by presenting an adaptive, high-performance approach to intrusion detection that effectively addresses challenges posed by evolving packet-mutation attacks, offering promising directions for nextgeneration NIDS development.
Original languageEnglish
Title of host publicationProceedings, 2024 22nd International Symposium on Network Computing and Applications
Subtitle of host publicationNCA 2024
EditorsJoann Wu
Place of PublicationPiscataway, NJ
PublisherIEEE
Pages227-235
Number of pages9
ISBN (Electronic)9798331510183
DOIs
Publication statusPublished - 2024
EventThe 22nd International Symposium on Network Computing and Applications 2024: NCA 2024 - Residential Center in Bertinoro, Bertinoro, Italy
Duration: 24 Oct 202426 Oct 2024
https://www.nca-ieee.org/2024/index.html
https://www.nca-ieee.org/2024/conference_program.html (Program)
https://www.nca-ieee.org/2024/call_for_papers.html (Call for papers)
https://doi.org/10.1109/NCA65406.2024 (Proceedings)

Publication series

NameProceedings - 2024 22nd International Symposium on Network Computing and Applications, NCA 2024

Conference

ConferenceThe 22nd International Symposium on Network Computing and Applications 2024
Country/TerritoryItaly
CityBertinoro
Period24/10/2426/10/24
OtherNCA is a successful series of conferences that serves as a large international forum for presenting and sharing recent research results and technological developments in the fields of Network and Cloud Computing. NCA, sponsored by the PE7 SERICS project, reaches out to both researchers and practitioners, and to both academia and industry.
Internet address

Fingerprint

Dive into the research topics of 'Enhancing network intrusion detection systems: A real-time adaptive machine learning approach for adversarial packet-mutation mitigation'. Together they form a unique fingerprint.

Cite this