A taxonomy and survey of intrusion detection system design techniques, network threats and datasets

Hindy, Hanan and Brosset, David and Bayne, Ethan and Seeam, Amar and Tachtatzis, Christos and Atkinson, Robert and Bellekens, Xavier (2018) A taxonomy and survey of intrusion detection system design techniques, network threats and datasets. Preprint / Working Paper. arXiv.org, Ithaca, N.Y..

[thumbnail of Hindy-etal-Arxiv-2018-A-taxonomy-and-survey-of-intrusion-detection-system-design]
Preview
Text. Filename: Hindy_etal_Arxiv_2018_A_taxonomy_and_survey_of_intrusion_detection_system_design.pdf
Final Published Version
License: Creative Commons Attribution 4.0 logo

Download (1MB)| Preview

Abstract

With the world moving towards being increasingly dependent on computers and automation, one of the main challenges in the current decade has been to build secure applications, systems and networks. Alongside these challenges, the number of threats is rising exponentially due to the attack surface increasing through numerous interfaces offered for each service. To alleviate the impact of these threats, researchers have proposed numerous solutions; however, current tools often fail to adapt to ever-changing architectures, associated threats and 0-days. This manuscript aims to provide researchers with a taxonomy and survey of current dataset composition and current Intrusion Detection Systems (IDS) capabilities and assets. These taxonomies and surveys aim to improve both the efficiency of IDS and the creation of datasets to build the next generation IDS as well as to reflect networks threats more accurately in future datasets. To this end, this manuscript also provides a taxonomy and survey or network threats and associated tools. The manuscript highlights that current IDS only cover 25% of our threat taxonomy, while current datasets demonstrate clear lack of real-network threats and attack representation, but rather include a large number of deprecated threats, hence limiting the accuracy of current machine learning IDS. Moreover, the taxonomies are open-sourced to allow public contributions through a Github repository.

ORCID iDs

Hindy, Hanan, Brosset, David, Bayne, Ethan, Seeam, Amar, Tachtatzis, Christos ORCID logoORCID: https://orcid.org/0000-0001-9150-6805, Atkinson, Robert ORCID logoORCID: https://orcid.org/0000-0002-6206-2229 and Bellekens, Xavier;