A Novel Framework for Generating Personalized Network Datasets for NIDS Based on Traffic Aggregation

In this paper, we addressed the problem of dataset scarcity for the task of network intrusion detection. Our main contribution was to develop a framework that provides a complete process for generating network traffic datasets based on the aggregation of real network traces. In addition, we proposed...

Full description

Bibliographic Details
Main Authors: Pablo Velarde-Alvarado, Hugo Gonzalez, Rafael Martínez-Peláez, Luis J. Mena, Alberto Ochoa-Brust, Efraín Moreno-García, Vanessa G. Félix, Rodolfo Ostos
Format: Article
Language:English
Published: MDPI AG 2022-02-01
Series:Sensors
Subjects:
Online Access:https://www.mdpi.com/1424-8220/22/5/1847
Description
Summary:In this paper, we addressed the problem of dataset scarcity for the task of network intrusion detection. Our main contribution was to develop a framework that provides a complete process for generating network traffic datasets based on the aggregation of real network traces. In addition, we proposed a set of tools for attribute extraction and labeling of traffic sessions. A new dataset with botnet network traffic was generated by the framework to assess our proposed method with machine learning algorithms suitable for unbalanced data. The performance of the classifiers was evaluated in terms of macro-averages of <i>F</i>1-score (0.97) and the Matthews Correlation Coefficient (0.94), showing a good overall performance average.
ISSN:1424-8220