Network Flow Integration to Improve Generalization of Machine Learning-Based IDS

  • Kelson Carvalho Santos UFU / IFPI
  • Rodrigo Sanches Miani UFU

Resumo


The growth of cyber threats and the evolution of attacks highlight the need for more robust machine learning-based IDS capable of operating in heterogeneous, dynamic network environments. Although some approaches presented in the literature improve the performance of these systems, their generalization capability remains limited in multi-domain data scenarios. This paper investigates supervised domain adaptation through controlled integration of labeled target-domain flows to diversify training and reduce generalization performance degradation in IDS. Results show improvements in specific scenarios, depending on the integrated flow type, with trade-offs among attack detection, class balance, and false alarms.

Referências

Aouini, Z. and Pekar, A. (2022). Nfstream: A flexible network data analysis framework. Computer Networks, 204:1–8.

Domingues, M., Bertoli, G., Melo, L., Saotome, O., Santos, A., and Pereira, L. (2022). Avaliação da capacidade de generalização de ids stateful utilizando aprendizado de máquina. In Anais do XXII SBSeg (2022), pages 236–249. SBC. Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), Santa Maria, RS, 12-15 Set 2023.

D’hooge, L., Wauters, T., Volckaert, B., and De Turck, F. (2020). Inter-dataset generalization strength of supervised machine learning methods for intrusion detection. Journal of Information Security and Applications, 54:1–13.

Kenyon, A., Deka, L., and D., E. (2020). Are public intrusion datasets fit for purpose characterising the state of the art in intrusion event datasets. Computers & Security, 99:1–26.

Layeghy, S. and Portmann, M. (2022). On generalisability of machine learning-based network intrusion detection systems. arXiv preprint arXiv:2205.04112, [s.n.]:1–12.

Mahfouz, A., Abuhussein, A., Venugopal, D., and Shiva, S. (2020). Ensemble classifiers for network intrusion detection using a novel network attack dataset. Future Internet, 12(11):1–19.

Marvi, M., Arfeen, A., and Uddin, R. (2021). A generalized machine learning-based model for the detection of ddos attacks. International Journal of Network Management, 31(6):1–22.

Molina-Coronado, B., Mori, U., Mendiburu, A., and Miguel-Alonso, J. (2020). Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Transactions on Network and Service Management, 17(4):2451–2479.

Moustafa, N. and Slay, J. (2015). A comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia, 10-12 Nov 2015.

Putra, W. and Huang, J. J. (2019). A survey of intrusion detection system. International Journal of Informatics and Computation, 1(1):1–19.

Rocha, M. S., Bernardo, G. D., Mundim, L., Zarpelão, B. B., and Miani, R. S. (2023). Supervised machine learning and detection of unknown attacks: An empirical evaluation. AINA 2023: International Conference on Advanced Information Networking and Applications, Juiz de Fora, MG, Brazil, 29-31 Mar 2023.

Santos, K. and Miani, R. (2025). Impacto da redução de dimensão e seleção de atributos na generalização de modelos de detecção de intrusão. In Anais do XLIII Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 728–741, Porto Alegre, RS, Brasil. SBC.

Santos, K. C., Miani, R. S., and de Oliveira Silva, F. (2024). Evaluating the impact of data preprocessing techniques on the performance of intrusion detection systems. Journal of Network and Systems Management, 32(36):1–54.

Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. 4th International Conference on Information Systems Security and Privacy (ICISSp), Funchal, Madeira, Portugal, 22-24 Jan 2018.

Sudyana, D., Lin, Y., Verkerken, M., Hwang, R., Lai, Y., D’Hooge, L., Wauters, T., Volckaert, B., and De Turck, F. (2024). Improving generalization of ml-based ids with lifecycle-based dataset, auto-learning features, and deep learning. IEEE Transactions on Machine Learning in Communications and Networking, 2:645–662.

Verkerken, M., D’hooge, L., Wauters, T., Volckaert, B., and De Turck, F. (2021). Towards model generalization for intrusion detection: Unsupervised machine learning techniques. Journal of Network and Systems Management, 30(1):1–25.

Zoppi, T., Ceccarelli, A., Puccetti, T., and Bondavalli, A. (2023). Which algorithm can detect unknown attacks? comparison of supervised, unsupervised and meta-learning algorithms for intrusion detection. Computers & Security, 127:1–12.
Publicado
01/09/2026
SANTOS, Kelson Carvalho; MIANI, Rodrigo Sanches. Network Flow Integration to Improve Generalization of Machine Learning-Based IDS. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 817-832. DOI: https://doi.org/10.5753/sbseg.2026.27867.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 > >>