Network Intrusion Detection System by Learning Jointly From Tabular and Text-Based Features

No Thumbnail Available

Date

2024

Journal Title

Journal ISSN

Volume Title

Publisher

Wiley

Open Access Color

HYBRID

Green Open Access

No

OpenAIRE Downloads

OpenAIRE Views

Publicly Funded

No
Impulse
Top 10%
Influence
Average
Popularity
Top 10%

Research Projects

Journal Issue

Abstract

Network intrusion detection systems (NIDS) play a critical role in maintaining the security and integrity of computer networks. These systems are designed to detect and respond to anomalous activities that may indicate malicious intent or unauthorized access. The need for robust NIDS solutions has never been more pressing in today's digital landscape, characterized by constantly evolving cyber threats. Deploying effective NIDS can be challenging, particularly in accurately identifying network anomalies amid the ever-increasing sophisticated and difficult-to-detect cyber threats. The motivation for our research stems from the recognition that while NIDS studies have made significant strides, there remains a crucial need for more effective and accurate methods to detect network anomalies. Commonly used features in NIDS studies include network logs, with some studies exploring text-based features such as payload. However, traditional machine and deep learning models may need to be improved in learning jointly from tabular and text-based features. Here, we present a new approach that integrates both tabular and text-based features to improve the performance of NIDS. Our research aims to address the existing limitations of NIDS and contribute to the development of more reliable and efficient network security solutions by introducing more effective and accurate methods for detecting network anomalies. Our internal experiments have revealed that the deep learning approach utilizing tabular features produces favourable results, whereas the pre-trained transformer approach needs to perform sufficiently. Hence, our proposed approach, which integrates both feature types using deep learning and pre-trained transformer approaches, achieves superior performance. These findings indicate that integrating both feature types using deep learning and pre-trained transformer approaches can significantly improve the accuracy of network anomaly detection. Moreover, our proposed approach outperforms the state-of-the-art methods in terms of accuracy, F1-score, and recall on commonly used NIDS datasets consisting of ISCX-IDS2012, UNSW-NB15, and CIC-IDS2017, with F1-scores of 99.80%, 92.37%, and 99.69%, respectively, indicating its effectiveness in detecting network anomalies.

Description

Cayir, Aykut/0000-0001-9564-0331; Unal, Ugur/0000-0001-6552-6044; Duzgun, Berkant/0000-0002-3637-4288

Keywords

CANINE, MLP, network logs, NIDS, payload, pre-trained transformer, tokenization-free

Turkish CoHE Thesis Center URL

Fields of Science

0202 electrical engineering, electronic engineering, information engineering, 02 engineering and technology

Citation

WoS Q

Q2

Scopus Q

Q1
OpenCitations Logo
OpenCitations Citation Count
N/A

Source

Expert Systems

Volume

41

Issue

4

Start Page

End Page

PlumX Metrics
Citations

Scopus : 14

Captures

Mendeley Readers : 45

SCOPUS™ Citations

14

checked on Feb 07, 2026

Web of Science™ Citations

8

checked on Feb 07, 2026

Page Views

36

checked on Feb 07, 2026

Google Scholar Logo
Google Scholar™
OpenAlex Logo
OpenAlex FWCI
5.71417979

Sustainable Development Goals

SDG data is not available