In the ever-evolving realm of network security, the swift and accurate identification of diverse attack classes within network traffic is of paramount importance. This paper introduces "ByteStack-ID," a pioneering approach tailored for packet-level intrusion detection. At its core, ByteStack-ID leverages grayscale images generated from the frequency distributions of payload data, a groundbreaking technique that greatly enhances the model's ability to discern intricate data patterns. Notably, our approach is exclusively grounded in packet-level information, a departure from conventional Network Intrusion Detection Systems (NIDS) that predominantly rely on flow-based data. While building upon the fundamental concept of stacking methodology, ByteStack-ID diverges from traditional stacking approaches. It seamlessly integrates additional meta learner layers into the concatenated base learners, creating a highly optimized, unified model. Empirical results unequivocally confirm the outstanding effectiveness of the ByteStack-ID framework, consistently outperforming baseline models and state-of-the-art approaches across pivotal performance metrics, including precision, recall, and F1-score. Impressively, our proposed approach achieves an exceptional 81\% macro F1-score in multiclass classification tasks. In a landscape marked by the continuous evolution of network threats, ByteStack-ID emerges as a robust and versatile security solution, relying solely on packet-level information extracted from network traffic data.
翻译:在网络安全的持续演进领域中,快速准确地识别网络流量中的多种攻击类别至关重要。本文提出"ByteStack-ID"这一创新方法,专用于数据包级别的入侵检测。其核心在于利用载荷数据频率分布生成的灰度图像,这一开创性技术显著增强了模型辨别复杂数据模式的能力。值得注意的是,本方法完全基于数据包级信息,这与传统网络入侵检测系统(NIDS)主要依赖流数据的做法形成鲜明对比。ByteStack-ID虽源于堆叠方法的基本概念,但突破了传统堆叠框架的局限,通过将额外元学习器层无缝集成至串联的基学习器中,构建出高度优化的统一模型。实验结果表明,ByteStack-ID框架在精确率、召回率和F1分数等关键性能指标上均显著优于基线模型与现有最先进方法。令人瞩目的是,本方法在多分类任务中实现了81%的宏平均F1分数。在网络威胁持续演变的背景下,ByteStack-ID仅依赖网络流量数据中的数据包级信息,展现出作为稳健且多功能安全解决方案的潜力。