vix.ing · top · new · best · stats · spec

Expectations Versus Reality: Evaluating Intrusion Detection Systems in Practice

2024/03/26 by Jake Hesford, Daniel Cheng, Hesford, Jake +11 · 2 citations
Computer Science · #68M20 #68M25 #C.4 #Cryptography and Security (cs.CR) #D.m #FOS: Computer and information sciences #Machine Learning (cs.LG) #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.2403.17458

openalex publication_date 2024/03/26 · openalex created_date 2024/03/30 · openalex updated_date 2026/07/28

Abstract

Our paper provides empirical comparisons between recent IDSs to provide an objective comparison between them to help users choose the most appropriate solution based on their requirements. Our results show that no one solution is the best, but is dependent on external variables such as the types of attacks, complexity, and network environment in the dataset. For example, BoTIoT and Stratosphere IoT datasets both capture IoT-related attacks, but the deep neural network performed the best when tested using the BoTIoT dataset while HELAD performed the best when tested using the Stratosphere IoT dataset. So although we found that a deep neural network solution had the highest average F1 scores on tested datasets, it is not always the best-performing one. We further discuss difficulties in using IDS from literature and project repositories, which complicated drawing definitive conclusions regarding IDS selection.

Cited by

Related