Options
The Missing Link in Network Intrusion Detection : taking AI/ML Research Efforts to Users
Dietz, Katharina; Mühlhauser, Michael; Kögel, Jochen; u. a. (2024): The Missing Link in Network Intrusion Detection : taking AI/ML Research Efforts to Users, in: IEEE access : practical research, open solutions, New York: IEEE, Jg. 12, S. 79815–79837, doi: 10.1109/access.2024.3406939.
Faculty/Chair:
Title of the Journal:
IEEE access : practical research, open solutions
ISSN:
2169-3536
Publisher Information:
Year of publication:
2024
Volume:
12
Pages:
Language:
German
Abstract:
Intrusion Detection Systems (IDS) tackle the challenging task of detecting network attacks as fast as possible. As this is getting more complex in modern enterprise networks, Artificial Intelligence (AI) and Machine Learning (ML) have gained substantial popularity in research. However, their adoption into real-world IDS solutions remains poor. Academic research often overlooks the interconnection of users and technical aspects. This leads to less explainable AI/ML models that hinder trust among AI/ML non-experts. Additionally, research often neglects secondary concerns such as usability and privacy. If IDS approaches conflict with current regulations or if administrators cannot deal with attacks more effectively, enterprises will not adopt the IDS in practice. To identify those problems systematically, our literature survey takes a user-centric approach; we examine IDS research from the perspective of stakeholders by applying the concept of personas. Further, we investigate multiple factors limiting the adoption of AI/ML in security and suggest technical, non-technical, and user-related considerations to enhance the adoption in practice. Our key contributions are threefold. (i) We derive personas from realistic enterprise scenarios, (ii) we provide a set of relevant hypotheses in the form of a review template, and (iii), based on our reviews, we derive design guidelines for practical implementations. To the best of our knowledge, this is the first paper that analyzes practical adoption barriers of AI/ML-based intrusion detection solutions concerning appropriateness of data, reproducibility, explainability, practicability, usability, and privacy. Our guidelines may help researchers to holistically evaluate their AI/ML-based IDS approaches to increase practical adoption.
Keywords: ; ; ; ; ; ; ;
Anomaly detection
artifcial intelligence
intrusion detection
machine learning
network monitoring
privacy
security
usability
Peer Reviewed:
Yes:
International Distribution:
Yes:
Type:
Article
Activation date:
June 3, 2024
Versioning
Question on publication
Permalink
https://fis.uni-bamberg.de/handle/uniba/95436