Bibliographic record
Abstract
An intrusion detection system (IDS) is an essential component of any modern network. The purpose of an IDS is to detect intrusion and generate appropriate alarms so that the intrusion can be mitigated. Implementing an IDS in a Software Defined Network (SDN) is easier since an SDN controller has a centralized view of the whole network. Researchers have made many efforts to use machine learning (ML) for developing network-based IDS in SDN. The network-based IDS analyzes different characteristics of incoming network traffic to detect intrusion. Early detection of intrusion is crucial for an IDS because if the intrusion is not detected quickly enough, it can cause severe damage, such as data breaches and service shutdowns. This paper focuses on detecting intrusion in SDN as early as possible using real-time flow-based features. Our aim is to detect intrusion with less amount of packets per flow, which not only facilitates early intrusion detection but also is useful when an intrusion flow has less number of packets. We show that although ML models perform well in offline training on a dataset, their performance decreases ~25% when fewer packets are used to generate features for the ML model. In all our experiments, a simple Random Forest (RF) algorithm outperforms a complex deep learning model on a publicly available dataset for intrusion detection in SDN.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.001 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".