Enhancing Anomaly-Based Intrusion Detection Systems with Process Mining

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Vitale, Francesco, Grimaldi, Francesco, Rak, Massimiliano, Mazzocca, Nicola
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917422517190656
author Vitale, Francesco
Grimaldi, Francesco
Rak, Massimiliano
Mazzocca, Nicola
author_facet Vitale, Francesco
Grimaldi, Francesco
Rak, Massimiliano
Mazzocca, Nicola
contents Anomaly-based Intrusion Detection Systems (IDSs) ensure protection against malicious attacks on networked systems. While deep learning-based IDSs achieve effective performance, their limited trustworthiness due to black-box architectures remains a critical constraint. Despite existing explainable techniques offering insight into the alarms raised by IDSs, they lack process-based explanations grounded in packet-level sequencing analysis. In this paper, we propose a method that employs process mining techniques to enhance anomaly-based IDSs by providing process-based alarm severity ratings and explanations for alerts. Our method prioritizes critical alerts and maintains visibility into network behavior, while minimizing disruption by allowing misclassified benign traffic to pass. We apply the method to the publicly available USB-IDS-TC dataset, which includes anomalous traffic affected by different variants of the Slowloris DoS attack. Results show that our method is able to discriminate between low- to very-high-severity alarms while preserving up to 99.94% recall and 99.99% precision, effectively discarding false positives while providing different degrees of severity for the true positives.
format Preprint
id arxiv_https___arxiv_org_abs_2604_18066
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Enhancing Anomaly-Based Intrusion Detection Systems with Process Mining
Vitale, Francesco
Grimaldi, Francesco
Rak, Massimiliano
Mazzocca, Nicola
Cryptography and Security
Machine Learning
Networking and Internet Architecture
Anomaly-based Intrusion Detection Systems (IDSs) ensure protection against malicious attacks on networked systems. While deep learning-based IDSs achieve effective performance, their limited trustworthiness due to black-box architectures remains a critical constraint. Despite existing explainable techniques offering insight into the alarms raised by IDSs, they lack process-based explanations grounded in packet-level sequencing analysis. In this paper, we propose a method that employs process mining techniques to enhance anomaly-based IDSs by providing process-based alarm severity ratings and explanations for alerts. Our method prioritizes critical alerts and maintains visibility into network behavior, while minimizing disruption by allowing misclassified benign traffic to pass. We apply the method to the publicly available USB-IDS-TC dataset, which includes anomalous traffic affected by different variants of the Slowloris DoS attack. Results show that our method is able to discriminate between low- to very-high-severity alarms while preserving up to 99.94% recall and 99.99% precision, effectively discarding false positives while providing different degrees of severity for the true positives.
title Enhancing Anomaly-Based Intrusion Detection Systems with Process Mining
topic Cryptography and Security
Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2604.18066