• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Wang, Maonan (Wang, Maonan.) | Zheng, Kangfeng (Zheng, Kangfeng.) | Yang, Yanqing (Yang, Yanqing.) | Wang, Xiujuan (Wang, Xiujuan.)

Indexed by:

EI Scopus SCIE

Abstract:

In recent years, machine learning-based intrusion detection systems (IDSs) have proven to be effective; especially, deep neural networks improve the detection rates of intrusion detection models. However, as models become more and more complex, people can hardly get the explanations behind their decisions. At the same time, most of the works about model interpretation focuses on other fields like computer vision, natural language processing, and biology. This leads to the fact that in practical use, cybersecurity experts can hardly optimize their decisions according to the judgments of the model. To solve these issues, a framework is proposed in this paper to give an explanation for IDSs. This framework uses SHapley Additive exPlanations (SHAP), and combines local and global explanations to improve the interpretation of IDSs. The local explanations give the reasons why the model makes certain decisions on the specific input. The global explanations give the important features extracted from IDSs, present the relationships between the feature values and different types of attacks. At the same time, the interpretations between two different classifiers, one-vs-all classifier and multiclass classifier, are compared. NSL-KDD dataset is used to test the feasibility of the framework. The framework proposed in this paper leads to improve the transparency of any IDS, and helps the cybersecurity staff have a better understanding of IDSs & x2019; judgments. Furthermore, the different interpretations between different kinds of classifiers can also help security experts better design the structures of the IDSs. More importantly, this work is unique in the intrusion detection field, presenting the first use of the SHAP method to give explanations for IDSs.

Keyword:

SHapley Additive exPlanations Machine learning Shapley value machine learning Biological system modeling Intrusion detection Predictive models Intrusion detection system Computational modeling Feature extraction model interpretation

Author Community:

  • [ 1 ] [Wang, Maonan]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 2 ] [Zheng, Kangfeng]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 3 ] [Yang, Yanqing]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 4 ] [Yang, Yanqing]Xinjiang Univ, Coll Informat Sci & Engn, Urumqi 830046, Peoples R China
  • [ 5 ] [Wang, Xiujuan]Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China

Reprint Author's Address:

  • [Zheng, Kangfeng]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China

Show more details

Related Keywords:

Related Article:

Source :

IEEE ACCESS

ISSN: 2169-3536

Year: 2020

Volume: 8

Page: 73127-73141

3 . 9 0 0

JCR@2022

Cited Count:

WoS CC Cited Count: 156

SCOPUS Cited Count: 228

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 14

Online/Total:1054/10532131
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.