Skip to main navigation Skip to search Skip to main content

Data-Driven Evaluation of Intrusion Detectors: A Methodological Framework

  • Solayman Ayoubi
  • , Gregory Blanc
  • , Houda Jmila
  • , Thomas Silverston
  • , Sébastien Tixeuil
  • Nancy Université
  • Telecom Sudparis
  • Sorbonne Université

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Citations (Scopus)

Abstract

Intrusion detection systems are an important domain in cybersecurity research. Countless solutions have been proposed, continuously improving upon one another. Yet, and despite the introduction of distinct approaches, including machine-learning methods, the evaluation methodology has barely evolved. In this paper, we design a comprehensive evaluation framework for Machine Learning (ML)-based intrusion detection systems (IDS) and take into account the unique aspects of ML algorithms, their strengths and weaknesses. The framework design is inspired by both i) traditional IDS evaluation methods and ii) recommendations for evaluating ML algorithms in diverse application areas. Data quality being the key to machine learning, we focus on data-driven evaluation by exploring data-related issues. Our approach goes beyond evaluating intrusion detection performance (also known as effectiveness) and aims at proposing standard data manipulation methods to tackle robustness and stability. Finally, we evaluate our framework through a qualitative comparison with other IDS evaluation approaches from the state of the art.

Original languageEnglish
Title of host publicationFoundations and Practice of Security - 15th International Symposium, FPS 2022, Revised Selected Papers
EditorsGuy-Vincent Jourdan, Laurent Mounier, Carlisle Adams, Florence Sèdes, Joaquin Garcia-Alfaro
PublisherSpringer Science and Business Media Deutschland GmbH
Pages142-157
Number of pages16
ISBN (Print)9783031301216
DOIs
Publication statusPublished - 1 Jan 2023
Event15th International Symposium on Foundations and Practice of Security, FPS 2022 - Ottawa, Canada
Duration: 12 Dec 202214 Dec 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13877 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Symposium on Foundations and Practice of Security, FPS 2022
Country/TerritoryCanada
CityOttawa
Period12/12/2214/12/22

Keywords

  • Data-driven Evaluation
  • Evaluation Framework
  • Intrusion Detection System
  • Machine learning

Fingerprint

Dive into the research topics of 'Data-Driven Evaluation of Intrusion Detectors: A Methodological Framework'. Together they form a unique fingerprint.

Cite this