Adaptive continual botnet detection with self-supervised prototypical networks and few-shot learning for evolving botnet detection
Adaptive continual botnet detection with self-supervised prototypical networks and few-shot learning for evolving botnet detection. INTRODUCTION: One of the problems faced by botnet intrusion detection systems is the detection of unknown attacks or zero-day attacks. Zero-day attacks give security analysts very little time for action since there is only little information that is known about the new attack that is launched, given very few samples available for the training process. Class imbalance issues faced by many benchmark datasets also reduce the ability to detect a zero-day attack. It leads to very few samples of a particular class, which makes it difficult to trace different types of the same attack. The rapid evolution of botnets also poses a challenge to the existing models, which often fail to adapt to the new attack patterns without catastrophic forgetting of previously learned knowledge. METHODS: The objective of this study was to develop a model for adaptive botnet detection in cases of zero-day attacks and imbalanced dataset availability. The study integrates self-supervised learning (SSL), enhanced prototypical networks with attention mechanisms, and few-shot learning (FSL) to overcome the existing issues. Wasserstein generative adversarial network with gradient penalty (WGAN-GP) generates synthetic samples to handle class imbalance. An adaptive continual learning module is used, which combines elastic weight consolidation (EWC) and an experience replay buffer which enables the model to accommodate new botnet behaviors while preserving performance on previously seen samples. Moreover, a drift detector using the KS test, Wasserstein distance, and class-prior shift triggers model adaptation when concept drift is identified. RESULTS: The performance of the proposed model was evaluated on the CIC IoT dataset 2023, which demonstrated an exceptional accuracy of 98.50%, outperforming the traditional baselines. Few-shot learning evaluations show strong genera…
0 Comments
The summary above is machine-written and the abstract is the authors' own pitch. This is where people who read the paper say what it actually found, what the summary missed, and which part is worth your time.
Log in to join the discussion.