基于Suricata与随机森林的被动混合网络入侵检测系统(Hybrid-NIDS)
Passive Hybrid Network-Based Intrusion Detection System (Hybrid-NIDS) Combining Suricata and Random Forest
浏览论文内容
中文总结 AI 辅助
本文评估了结合Suricata与随机森林的被动混合入侵检测系统原型,发现其在公共基准上表现优异,但在实际部署中因领域偏移导致检测性能大幅下降,表明基准性能不能直接转化为操作有效性。
中文摘要 AI 辅助
本文评估了一个被动混合网络入侵检测系统(Hybrid-NIDS)原型,该系统将Suricata与随机森林流分类以及基于ELK的集中式告警处理相结合。研究明确将基准测试评估与PCAP/实况操作验证分开,并使用特征哈希和分组感知分割来控制精确的特征重复泄漏。从2,540,047条UNSW-NB15记录中,移除了包含1,879行的453个冲突标签哈希组;由此得到的开发集和留出集具有零精确特征哈希重叠。RF-41在相同的准备好的留出边界上实现了F1=0.971360和ROC-AUC=0.999671,而兼容NFStream的RF-21实现了F1=0.970148。然而,操作验证揭示了从基准到部署的显著领域偏移:在标记的实验室PCAP上,RF-21和严格相关分支仅实现了0.0095的召回率,且RF-21在另外五个60秒攻击会话中未产生任何告警。一个未标记的正常流量测试从2,375条流中产生了439条告警;该值仅作为告警比率报告,不被解释为误报率。这些结果表明,在公共基准上的强性能并不能直接转化为操作有效性。因此,当前的Hybrid-NIDS应被解释为被动原型和评估框架,所报告的实验并未证明Suricata-随机森林相关性比单独使用Suricata提供更好的操作检测能力。
英文摘要
This paper evaluates a passive Hybrid Network-based Intrusion Detection System (Hybrid-NIDS) prototype that combines Suricata with Random Forest flow classification and centralized ELK-based alert handling. The study explicitly separates benchmark evaluation from PCAP/live operational validation and controls exact feature-duplicate leakage using feature hashing and group-aware splitting. From 2,540,047 UNSW-NB15 records, 453 conflicting-label hash groups containing 1,879 rows were removed; the resulting Development and Hold-out sets have zero exact feature-hash overlap. RF-41 achieved F1 = 0.971360 and ROC-AUC = 0.999671, while the NFStream-compatible RF-21 achieved F1 = 0.970148 on the same prepared hold-out boundary. However, operational validation revealed substantial benchmark-to-deployment domain shift: on a labeled laboratory PCAP, RF-21 and the strictly correlated branch achieved recall of only 0.0095, and RF-21 produced no alerts in five additional 60-second attack sessions. An unlabeled normal-traffic test produced 439 alerts from 2,375 flows; this value is reported only as an alert ratio and is not interpreted as a false-positive rate. These results show that strong performance on a public benchmark does not directly translate into operational effectiveness. Accordingly, the current Hybrid-NIDS should be interpreted as a passive prototype and evaluation framework, and the reported experiments do not demonstrate that Suricata-Random Forest correlation provides better operational detection than Suricata alone.
发表机构
- Ho Chi Minh City College of Transport(胡志明市交通学院)
- Academy of Cryptography Techniques, Ho Chi Minh City Campus(密码技术学院胡志明市校区)
- Faculty of Computer Science and Engineering, Ho Chi Minh City University of Technology (HCMUT)(胡志明市理工大学计算机科学与工程系)
- Vietnam National University Ho Chi Minh City(越南国家大学胡志明市分校)
机构由 AI 辅助整理,请以论文原文为准。