Deep Reinforcement Learning based Network Intrusion Classification

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

UIU

DOI

Abstract

Network intrusion classification referred to the process of monitoring and analyzing network traffic to identify suspicious activities or attacks. In this work, author proposed a novel approach to classify network intrusion by utilizing deep reinforcement learning (DRL), integrating a hybrid deep learning model architecture that combined Deep Neural Network (DNN) and Long Short-Term Memory (LSTM) networks. A DRL-based approach improved upon traditional deep learning by adapting dynamically to novel/unknown and evolving attack patterns. Unlike static models, DRL continuously learned optimal strate￾gies through interaction with the environment, allowing for better detection of previously unseen threats in real-time. To address the class imbalance often encountered in net￾work intrusion datasets, I evaluated the performance of several advanced data balancing techniques, including Borderline-SMOTE, SMOTE-ENN, ADYSN, and K-means SMOTE. The findings demonstrated that the K-means-based data balancing method outperformed other techniques, resulting in the most robust performance across various metrics. Au￾thor conducted multi-dataset validation to ensure robustness across different network flow data. For adaptive modeling testing, author excluded some attack types from training data and included them in testing data (e.g., DoS attacks were excluded from the training data but included in the testing data). The proposed approach enhanced the accuracy and reliability of intrusion detection, making it a viable solution for securing modern network infrastructures.

Description

Citation

Endorsement

Review

Supplemented By

Referenced By