Trust-Aware Iterative Monitoring for False Alarm Reduction in Intrusion Detection Systems
Notice bibliographique
Résumé
In recent years with the advent of high frequency cyber activities, Intrusion Detection Systems (IDS) are an important means to keep digital environments safe from the neverending and continually escalating cyber threats.However, the main difficulty that IDS deployments encounter is the high level of false positive rates.Such false positives may cause human and computational resources to be wasted and their visibility of real threats tarnished, resulting in delayed or missed responses.The accurate prediction is not only capable of preventing infections spreading, but also endowed with potential properties of cyber forensics.Based on this research, the authors suggest a new solution, called the Iterative Monitoring Model (IMM) combined with a Trusted Trained Model (TTM) for improving the intrusion detection and substantially decreasing the false alarms.The IMM operates in perpetual learning and adaptation.Feedback from earlier detections is feedback into the training.By incorporating iterative learning and trust assessment, our model guarantees that the priority is assigned to the authentic alerts, while the misleading or legitimate anomalies are filtered.This two-model architecture increases the accuracy of detection mechanisms, builds trust in system outputs, and decreases the cognitive load on security operators.Experiments on benchmark datasets show that the proposed model outperforms traditional IDS solutions so that the false positives are improved by more than 40% with ahigh detection rate.Comparing IMM to state-of-the-art IDS models, experimental assessments showed that it improved accuracy by more than 3-4%, reaching 95.78% on the NSL-KDD dataset and 93.41% on the UNSW-NB15 dataset.With a recall of 96.42% on NSL-KDD and 94.04% on UNSW-NB15, this iterative adaptation makes sure that real dangers are almost never missed.The False Alarm Rate (FAR) drops to 2.13% on NSL-KDD and 3.45% on UNSW-NB15 because to this validation process, which is a 40% reduction compared to previous IDS solutions.Analysts can be assured that the warnings provided will be accurate because the accuracy is increased to 94.25% and 91.78%.In general, the contributions of this work are a scalable, adaptive, and reliable architecture to cyber security which can change the approach in the real time for managing network-based threats.
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction machine sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.
Scores du classifieur distillé par catégorie (deux têtes)
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,002 | 0,010 |
| Méta-épidémiologie (sens strict) | 0,001 | 0,001 |
| Méta-épidémiologie (sens large) | 0,001 | 0,001 |
| Bibliométrie | 0,001 | 0,000 |
| Études des sciences et des technologies | 0,001 | 0,001 |
| Communication savante | 0,001 | 0,002 |
| Science ouverte | 0,002 | 0,001 |
| Intégrité de la recherche | 0,001 | 0,002 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,001 | 0,000 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».