[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125540-en":3,"doc-seo-125540-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125540,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","A Hypergraph-Based Machine Learning Ensemble Network Intrusion Detection System - arXiv 2211.03933","Network intrusion detection systems (NIDS) face vulnerabilities to auto-generated port scan infiltration and are often developed offline, causing delays when attacks propagate through a network. This work introduces hypergraphs to model evolving port scan patterns using sets of IP addresses and destination ports. The approach trains a robust ensemble ML NIDS with hypergraph-based metrics, integrating intrusion examples, NIDS update rules, and retraining trigger thresholds, then evaluates auto-generated attack scenarios under real-time production-like conditions. Results show nearly 100% detection performance with the Update-ALL-NIDS update rule.","arXiv :2211 .03933v1 [ cs .CR] 8 Nov 2022  \nA Hypergraph-Based Machine Learning Ensemble Network Intrusion Detection System  \nZong-Zhi Lin, Thomas D. Pike, Mark M. Bailey  \nDepartment of Cyber Intelligence and Data Science  \nNational Intelligence University  \nBethesda, Maryland, USA  \n[alexzzlin@gmail.com](alexzzlin@gmail.com), [thomas.d.pike@odni.gov](thomas.d.pike@odni.gov), [mark.m.bailey@odni.gov](mark.m.bailey@odni.gov)  \nNathaniel D. Bastian  \nArmy Cyber Institute  \nUnited States Military Academy  \nWest Point, New York, USA  \n[nathaniel.bastian@westpoint.edu](nathaniel.bastian@westpoint.edu)  \nAbstract—Network intrusion detection systems (NIDS) to detect malicious attacks continues to meet challenges. NIDS are vulnerable to auto-generated port scan inﬁltration attempts and NIDS are often developed ofﬂine, resulting in a time lag to prevent the spread of inﬁltration to other parts of a network. To address these challenges, we use hypergraphs to capture evolving patterns of port scan attacks via the set of internet protocol addresses and destination ports, thereby deriving a set of hypergraph-based metrics to train a robust and resilient ensemble machine learning (ML) NIDS that effectively monitors and detects port scanning activities and adversarial intrusions while evolving intelligently in real-time. Through the combination of (1) intrusion examples,(2) NIDS update rules,(3) attack threshold choices to trigger NIDS retraining requests, and (4) production environment with no prior knowledge of the nature of network trafﬁc 40 scenarios were auto-generated to evaluate the ML ensemble NIDS comprising three treebased models. Results show that under the model settings of an Update-ALL-NIDS rule (namely, retrain and update all the three models upon the same NIDS retraining request) the proposed ML ensemble NIDS produced the best results with nearly 100% detection performance throughout the simulation, exhibiting robustness in the complex dynamics of the simulated cyber-security scenario.  \nIndex Terms—Machine Learning, Network Science, Intrusion Detection, Adversarial Machine Learning, Intelligent Systems.  \nI. INTRODUCTION  \nTO defend against unauthorized and unauthenticated  \naccess in the internet-connected networks of systems an effective and efﬁcient cybersecurity system and organizational process must be established. However, the increase in network size and network activities have posed considerable challenges for the limited human resources and their comparatively slow pace to adapt against cyberthreats. Furthermore, the rapid advances in internet and communication technologies continue to introduce increasingly complex dynamics comprising of more variants of cyberthreats, such as malware, phishing, port scanning, and denial-of-service attack, to name just a few. These rapidly evolving network  \nsecurity threats and the need to detect, characterize and defend against diverse and adapting cyberattacks necessitate the use of machine learning techniques [1] .  \nMachine learning (ML) techniques with varying degrees of sophistication and complexity seek to effectively andefﬁciently detect intrusions and the approaches can be categorized in the seminal ML categories as either supervised or unsupervised learning algorithms [2] . Supervised learning algorithms learn from labeled data (e.g. data labeled as known intrusion attempt), whereas unsupervised learning algorithms extracts valuable insights from unlabeled data. These ML methods often require large amounts of network trafﬁc data with laboriously developed data features to train network intrusion detection systems [3],[4]. To overcome this training data challenge, transfer learning can be employed to leverage the curated data from network trafﬁc and apply it to another, without necessarily needing to use the same ML approach [5] .  \nRegardless of the approach, ML-based network intrusion detection systems (NIDS) continue to struggle to develop approaches that produce effec","cbCairV7WCT8bRRq","https://ap.wps.com/l/cbCairV7WCT8bRRq","pdf",633418,1,12,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What problem does the intrusion detection system address?\",\"answer\":\"It targets challenges where NIDS are vulnerable to auto-generated port scan infiltration and where offline development creates time lag as attacks spread across networks.\"},{\"question\":\"How does the proposed method model port scan behavior?\",\"answer\":\"It uses hypergraphs to capture evolving port scan patterns based on sets of internet protocol addresses and destination ports, then derives hypergraph-based metrics for training.\"},{\"question\":\"What update strategy produces the best detection results?\",\"answer\":\"The Update-ALL-NIDS rule, which retrains and updates all three ensemble models using the same NIDS retraining request, yields nearly 100% detection performance in simulation.\"}]","A Hypergraph-Based Machine Learning Ensemble Network Intrusion Detection System - arXiv 2211.03933 | PDF",1785899742,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-hypergraph-based-machine-learning-ensemble-network-intrusion-detection-system-arxiv-221103933","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-hypergraph-based-machine-learning-ensemble-network-intrusion-detection-system-arxiv-221103933/125540/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the intrusion detection system address?","Question",{"text":75,"@type":76},"It targets challenges where NIDS are vulnerable to auto-generated port scan infiltration and where offline development creates time lag as attacks spread across networks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed method model port scan behavior?",{"text":80,"@type":76},"It uses hypergraphs to capture evolving port scan patterns based on sets of internet protocol addresses and destination ports, then derives hypergraph-based metrics for training.",{"name":82,"@type":73,"acceptedAnswer":83},"What update strategy produces the best detection results?",{"text":84,"@type":76},"The Update-ALL-NIDS rule, which retrains and updates all three ensemble models using the same NIDS retraining request, yields nearly 100% detection performance in simulation.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]