Concept drift is of primary concern for the detection of attacks in Internet traffic networks. Those networks register a high diversity of heterogeneous activity which change with usage, thus nurturing an evolutive environment. Detecting attacks is the action of dissociating attacks from the other data in the environment in a discriminating classification. However, both the modification of attack behaviors through time and the evolution of the environment are disruptive of the thin boundaries drawn by learning models. For the evaluation of sustainability and trustworthiness of the detection system, concept drift detection approaches have emerged. Those approaches can necessitate a significant amount of time and resources to mitigate the effect of concept drift thus detected.
In this paper we propose an end-to-end approach in the production of a concept drift robust feature space and its evaluation for learning models. We define t-robustness as a quantification of feature drift, design a feature engineering approach using initial learning conditions to mitigate the effect of concept drift on learning models, and define metrics to evaluate the stability of learning models. We apply our approach on the UGR16 dataset enriched with graph community metrics. The features produced by our graph community metrics extraction approach have very few dependencies in their construction, which make them relevant for time robust attack detection. Hence, we produce a feature space which produces more stable detection models through time.
- Venue: 29th International Conference on Knowledge-Based and Intelligent Information & Engineering Systems (KES 2025), Osaka, Japan — Procedia Computer Science
- HAL record: hal-05098355
- PDF: download
- Co-authors: Julien Michel