Pillars of Sand: The current state of Datasets in the field of Network Intrusion Detection
Authors/Creators
- 1. imec-DistriNet, KU Leuven
- 2. University of Edinburgh
- 3. School of Engineering and IT, University of New South Wales
Description
Abstract—Network Intrusion Detection Systems play a critical role in protecting network architectures from harm. In the past decade, Machine Learning has moved to the forefront of research in this field, with many approaches resulting in great performance on benchmark NIDS datasets. The relevance of these performance results is however directly tied to the quality of the benchmark datasets used for training, which have so far not been subjected to thorough analysis. As part of our work, we have performed a large-scale manual investigation of the most commonly used publicly available NIDS datasets, where we have uncovered numerous errors due to problems in data pre-processing, attack simulation and labelling. We also highlight the lack of variability in both benign and malicious traffic, which often renders the classification task trivial. To quantify this variability, we have devised an automated methodology that can be applied without requiring expert domain knowledge. Nevertheless, we believe it is vital for any NIDS benchmark datasets to undergo a thorough manual analysis before being widely adopted. As a follow-up of our previous work where we provided an improved version of the CICIDS 2017 dataset, we are also actively working on improving the CSE-CICIDS 2018 dataset, which we intend to release to the research community.
Notes
Files
eurosp22posters-final27-1-3.pdf
Files
(129.8 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:554a3aa071f14581810f397271448f3c
|
129.8 kB | Preview Download |
Additional details
Related works
- Is part of
- Poster: 10.5281/zenodo.7068698 (DOI)