Published June 6, 2022 | Version v1

Pillars of Sand: The current state of Datasets in the field of Network Intrusion Detection

  • 1. imec-DistriNet, KU Leuven
  • 2. University of Edinburgh
  • 3. School of Engineering and IT, University of New South Wales

Description

Abstract—Network Intrusion Detection Systems play a critical role in protecting network architectures from harm. In the past decade, Machine Learning has moved to the forefront of research in this field, with many approaches resulting in great performance on benchmark NIDS datasets. The relevance of these performance results is however directly tied to the quality of the benchmark datasets used for training, which have so far not been subjected to thorough analysis. As part of our work, we have performed a large-scale manual investigation of the most commonly used publicly available NIDS datasets, where we have uncovered numerous errors due to problems in data pre-processing, attack simulation and labelling. We also highlight the lack of variability in both benign and malicious traffic, which often renders the classification task trivial. To quantify this variability, we have devised an automated methodology that can be applied without requiring expert domain knowledge. Nevertheless, we believe it is vital for any NIDS benchmark datasets to undergo a thorough manual analysis before being widely adopted. As a follow-up of our previous work where we provided an improved version of the CICIDS 2017 dataset, we are also actively working on improving the CSE-CICIDS 2018 dataset, which we intend to release to the research community.

Notes

The poster was accepted at the 7th IEEE European Symposium on Security and Privacy (Euro S&P 2022) and presented in the poster session. Original poster: https://ieeeeurosp.github.io/2022/posters/

Files

eurosp22posters-final27-1-3.pdf

Files (129.8 kB)

Name Size Download all
md5:554a3aa071f14581810f397271448f3c
129.8 kB Preview Download

Additional details

Related works

Is part of
Poster: 10.5281/zenodo.7068698 (DOI)