发表机构
Department of Computer Science; New Mexico State University; Graduate School of Informatics; Osaka Metropolitan University(计算机科学系; 新墨西哥州立大学; 信息科学研究生院; 大阪 metropolitan 大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对网络入侵检测中误报问题,提出BARS方法,它是两阶段过滤器,用良性类均值取代全局锚并去相关。实验表明在攻击占优数据集上能降误报率,保持真阳性率和宏F1,适合资源受限部署。
AI 中文摘要
误报仍然是部署网络入侵检测系统(NIDS)的主要障碍。在高流量环境中,即使低于1%的误报率每天也会产生数万条警报。基于过滤器的特征选择很有吸引力,因为它在分类器上游运行且不增加推理时间成本。经典过滤器使用类对称标准,忽略了入侵检测的不对称性,良性流量定义基线,攻击是其偏差。最近的类不对称过滤器Classwise Mean Deviation(CMD)解决了这个问题,但将分数锚定到全局均值,在类不平衡时向攻击分布偏移,削弱了它旨在捕获的偏差。我们提出了良性锚定排序与选择(BARS),一个两阶段过滤器,用良性类均值取代CMD的全局锚,并应用保序去相关步骤。我们在CICIDS2017、CICDDoS2019和UNSW-NB15上使用特征预算k = {5, 10, 20, 30, 40}评估BARS。在攻击占多数的数据集上,BARS相对于CMD降低了误报率,在k = 20时,在UNSW-NB上降低了15.4%,在小特征预算下,在CICDDoS2019上降低了21%到23%,同时保持真阳性率和宏F1。在良性占多数的数据上,BARS和CMD收敛。BARS是CMD的原则性改进,而非普遍占优的过滤器。虽然Pearson相关性和互信息通常能实现更低的误报率,但在我们评估的最大基准上超过了1 TB内存。BARS保留线性时间评分和低内存占用,适合资源受限的部署。
英文摘要
False alarms remain a major barrier to deploying network intrusion detection systems (NIDS). In high-volume environments, even a sub-1% false positive rate can generate tens of thousands of daily alerts. Filter-based feature selection is attractive because it operates upstream of the classifier and adds no inference-time cost. However, classical filters use class-symmetric criteria that ignore the asymmetry of intrusion detection, where benign traffic defines the baseline and attacks are deviations from it. A recent class-asymmetric filter, Classwise Mean Deviation (CMD), addresses this issue but anchors its score to a global mean that shifts toward attack distributions under class imbalance, weakening the deviations it aims to capture. We propose Benign-Anchored Ranking and Selection (BARS), a two-stage filter that replaces CMD's global anchor with the benign-class mean and applies an order-preserving decorrelation step. We evaluate BARS on CICIDS2017, CICDDoS2019, and UNSW-NB15 using feature budgets k = {5, 10, 20, 30, 40}. On attack-majority datasets, where global-anchor bias is strongest, BARS reduces false positive rate relative to CMD by 15.4% on UNSW-NB15 at k = 20 and by 21% to 23% on CICDDoS2019 at small feature budgets while preserving true positive rate and macro-F1. On benign-majority data, BARS and CMD converge, consistent with the theoretical limit where global- and benign-anchored scores coincide. BARS reduces false alarms by up to 32% while maintaining similar detection rates, with larger gains under stronger imbalance. Ablation results show that the two stages provide complementary benefits and select a consistent set of robust features. BARS retains linear-time scoring and a low memory footprint, making it suitable for resource-constrained deployments.