Practical Performance of a Distributed Processing Framework for Machine-Learning-based NIDS

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Kajiura, Maho, Nakamura, Junya
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866929353551511552
author Kajiura, Maho
Nakamura, Junya
author_facet Kajiura, Maho
Nakamura, Junya
contents Network Intrusion Detection Systems (NIDSs) detect intrusion attacks in network traffic. In particular, machine-learning-based NIDSs have attracted attention because of their high detection rates of unknown attacks. A distributed processing framework for machine-learning-based NIDSs employing a scalable distributed stream processing system has been proposed in the literature. However, its performance, when machine-learning-based classifiers are implemented has not been comprehensively evaluated. In this study, we implement five representative classifiers (Decision Tree, Random Forest, Naive Bayes, SVM, and kNN) based on this framework and evaluate their throughput and latency. By conducting the experimental measurements, we investigate the difference in the processing performance among these classifiers and the bottlenecks in the processing performance of the framework.
format Preprint
id arxiv_https___arxiv_org_abs_2405_13066
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Practical Performance of a Distributed Processing Framework for Machine-Learning-based NIDS
Kajiura, Maho
Nakamura, Junya
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
Networking and Internet Architecture
Network Intrusion Detection Systems (NIDSs) detect intrusion attacks in network traffic. In particular, machine-learning-based NIDSs have attracted attention because of their high detection rates of unknown attacks. A distributed processing framework for machine-learning-based NIDSs employing a scalable distributed stream processing system has been proposed in the literature. However, its performance, when machine-learning-based classifiers are implemented has not been comprehensively evaluated. In this study, we implement five representative classifiers (Decision Tree, Random Forest, Naive Bayes, SVM, and kNN) based on this framework and evaluate their throughput and latency. By conducting the experimental measurements, we investigate the difference in the processing performance among these classifiers and the bottlenecks in the processing performance of the framework.
title Practical Performance of a Distributed Processing Framework for Machine-Learning-based NIDS
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2405.13066