Back to results

University of Ontario Institute of Technology

DL-based defense against polymorphic network attacks

Abstract

dc:description.abstract

Network security is of vital importance in our world dominated by internet systems. These systems are vulnerable to large-scale rapidly evolving attacks by sophisticated cyber attackers who can have an upper edge over the defensive systems. Artificial Intelligence (AI) based intrusion detection systems provide effective defense mechanisms against cyber attacks. However, these techniques often rely on the same dataset for training and validation as well as evaluation of AI models. Current research [1] also confirms that such trained models can accurately identify known/typical network attacks but perform poorly when faced with continuously evolving atypical/polymorphic cyberattacks. Therefore, it is crucial to develop and train an AI-based Intrusion Detection System (IDS) that proactively learns to resist infiltration by such dynamically changing attacks. For this purpose, in this research work, we propose an AI-based IDS system that can monitor and detect polymorphic network attacks with high confidence levels. We propose a novel hybrid adversarial model that leverages the best characteristics of a Conditional Variational Autoencoder (CVAE) and a Generative Adversarial Network (GAN). Our system generates adversarial polymorphic attacks against the IDS to examine its performance and incrementally retrains it to strengthen its detection of new attacks, specifically for minority attack samples in the input data. The employed attack quality analysis ensures that the adversarial atypical/polymorphic attacks generated through our system resemble realistic network attacks. Our experiments showcase the exceptional performance of the proposed IDS by training it using the CICIDS2017 and CICIoT2023 benchmark datasets and evaluating its performance against several atypical/polymorphic attack flows. The results indicate that the proposed technique, through adaptive training, learns the pattern of dynamically changing atypical/polymorphic attacks and identifies such attacks with high IDS proficiency. Additionally, our IDS surpasses various state-of-the-art anomaly detection and class balancing techniques.

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy (PhD)
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Ontario Institute of Technology
Year dc:date.issued
2024

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Sabeel, Ulya
Advisors dc:contributor.advisor
  • Heydari, Shahram
  • El-Khatib, Khalil

Subjects

dc:subject × 5

Rights

Language dc:language.iso
en

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10155/1759
OAI identifier oai:identifier
oai:ontariotechu.scholaris.ca:10155/1759

Chain of custody

source
Harvested from
Ontario Institute of Technology
Base URL
ontariotechu.scholaris.ca/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Sabeel, Ulya. DL-based defense against polymorphic network attacks. University of Ontario Institute of Technology, 2024. https://hdl.handle.net/10155/1759