1
کارشناسی ارشد، گروه مهندسی کامپیوتر، دانشگاه بیرجند، ایران
2
گروه برق واحد دولت آباد دانشگاه آزاد اسلامی، اصفهان، ایران
3
گروه برق و کامپیوتر، واحد تربت حیدریه، دانشگاه آزاد اسلامی، تربت حیدریه، ایران
10.22034/csj.2025.227853
چکیده
امروزه، شبکههای کامپیوتری نقش بسیار مهمی در ارتباطات و تبادل دادهها داشته و گسترش این شبکهها شرایط مناسبی را برای حملات سایبری و نفوذ فراهم کرده است. نفوذ یکی از فعالیتهای غیرقانونی است که امنیت اطلاعات و محرمانیت را به خطر میاندازد و یا دسترسی غیرمجاز به منابع سازمانی را فراهم میکند. سیستمهای تشخیص نفوذ (IDS)، عامل مهمی هستند و حملاتی را که توسط باروهای[1] سنتی قابل رصد نیستند، شناسایی میکنند. با این حال، حملات مختلف رفتارهای خاص خود را دارند و بهبود تشخیص نوع حمله همچنان یکی از چالشهای مدلهای تشخیص نفوذ محسوب میشود. برای حل مشکلات مربوط به توسعه سیستمهای تشخیص نفوذ (IDS)، محققان بسیاری به تمرکز بر روشهای یادگیری ماشین و یادگیری عمیق پرداختهاند. این روشها قادرند به طور خودکار تفاوتهای اساسی بین دادههای معمولی و دادههای غیرطبیعی را کشف کنند و همچنین قابلیت تعمیم قوی دارند که این امر امکان شناسایی حملات ناشناخته را فراهم میکند. در این پژوهش به بررسی روشهای مختلف تشخیص نفوذ با استفاده از یادگیری ماشین میپردازیم این چارچوب طبقهبندی برای امنیت سایبری مناسب است و محققان در این بررسی به مفهوم و طبقهبندی IDSها، الگوریتمهای یادگیری ماشین و یادگیری عمیق، و چالشها و تحولات آتی در این حوزه پرداختهاند.
Ozkan-Okay, M., Samet, R., Aslan, Ö., & Gupta, D. (2021). A comprehensive systematic literature review on intrusion detection systems. IEEE Access, 9, 157727-157760.
Thakkar, A., & Lohiya, R. (2022). A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artificial Intelligence Review, 55(1), 453-563.
Hande, Y., & Muddana, A. (2021). A survey on intrusion detection system for software defined networks (SDN). In Research Anthology on Artificial Intelligence Applications in Security (pp. 467-489). IGI Global.
Anderson, J.P. (1980). Computer Security Threat Monitoring and Surveillance; Technical Report; James P. Anderson Company: Philadelphia, PA , USA.
Michie, D.; Spiegelhalter, D.J.; Taylor, C. (1994). Machine Learning, Neurall and Statistical Classification; Ellis Horwood Series in Artificial Intelligence: New York, NY, USA, Volume 13.
Buczak, A.L., & Guven, E. A. (2015). survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 18, 1153–1176. [CrossRef]
Mohammadi, M., Rashid, T. A., Karim, S. H. T., Aldalwie, A. H. M., Tho, Q. T., Bidaki, M., ... & Hosseinzadeh, M. (2021). A comprehensive survey and taxonomy of the SVM-based intrusion detection systems. Journal of Network and Computer Applications, 178, 102983.
Asharf, J., Moustafa, N., Khurshid, H., Debie, E., Haider, W., & Wahab, A. (2020). A review of intrusion detection systems using machine and deep learning in internet of things: Challenges, solutions and future directions. Electronics, 9(7), 1177.
Dina, A. S., & Manivannan, D. (2021). Intrusion detection based on machine learning techniques in computer networks. Internet of Things, 16, 100462.
Aldweesh, A., Derhab, A., & Emam, A. Z. (2020). Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues. Knowledge-Based Systems, 189, 105124.
Díaz-Verdejo, J., Muñoz-Calle, J., Estepa Alonso, A., Estepa Alonso, R., & Madinabeitia, G. (2022). On the detection capabilities of signature-based intrusion detection systems in the context of web attacks. Applied Sciences, 12(2), 852.
Mebawondu, J. O., Alowolodu, O. D., Mebawondu, J. O., & Adetunmbi, A. O. (2020). Network intrusion detection system using supervised learning paradigm. Scientific African, 9, e00497.
Ashfaq RAR, Wang X-Z, Huang JZ et al. (2017). Fuzziness based semisupervised learning approach for intrusion detection system. Inf Sci 378:484–497. https ://doi.org/10.1016/j.ins.2016.04.019
Aljawarneh, S., Aldwairi, M., & Yassein, MB. (2018). Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. J Comput Sci 25:152–160. https ://doi.org/10.1016/j.jocs.2017.03.006
Dhanabal, L., & Shantharajah, DSP. (2015). A study on NSL-KDD dataset for intrusion detection system based on classification algorithms. Int J Adv Res Comput Commun Eng 4:446–452
Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, AA. (2009). A detailed analysis of the KDD CUP 99 data set. In: Symposium on Computational Intelligence for Security and Defense Applications. Pp 1–6
Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Inf Secur J Glob Perspect 25:18–31. https //doi.org/10.1080/19393 555.2015.11259 74
Ambusaidi, MA., He, X., Nanda, P., & Tan, Z. (2016). Building an intrusion detection system using a filter-based feature selection algorithm. IEEE Trans Comput 65:2986–2998. https ://doi.org/10.1109/ TC.2016.25199 14
Yao, H., Fu, D., Zhang, P., Li, M., & Liu, Y. (2019). Msml: a novel multilevel semi-supervised machine learning framework for intrusion detection system. IEEE Int Things J. 6(2):1949–59. https://doi.org/10.1109/JIOT.2018.2873125.
Talaei Khoei, T., & Kaabouch, N. (2023). A Comparative Analysis of Supervised and Unsupervised Models for Detecting Attacks on the Intrusion Detection Systems. Information, 14(2), 103.
Alrayes, F. S., Zakariah, M., Amin, S. U., Khan, Z. I., & Helal, M. (2024). Intrusion detection in IoT systems using denoising autoencoder. IEEE Access..
Maithem, M., & Al-Sultany, G. A. (2021, February). Network intrusion detection system using deep neural networks. In Journal of Physics: Conference Series (Vol. 1804, No. 1, p. 012138). IOP Publishing.
Abd, S. N., Alsajri, M., & Ibraheem, H. R. (2020). Rao-SVM machine learning algorithm for intrusion detection system. Iraqi Journal For Computer Science and Mathematics, 1(1), 23-27.
Wazirali, R. (2020). An improved intrusion detection system based on KNN hyperparameter tuning and cross-validation. Arabian Journal for Science and Engineering, 45(12), 10859-10873.
Kurniawan, Y. I., Razi, F., Nofiyati, N., Wijayanto, B., & Hidayat, M. L. (2021). I Bayes modification for intrusion detection system classification with zero probability. Bulletin of Electrical Engineering and Informatics, 10(5), 2751-2758.
Razdan, S., Gupta, H., & Seth, A. (2021, April). Performance analysis of network intrusion detection systems using j48Inaive bayes algorithms. In 2021 6th International Conference for Convergence in Technology (I2CT) (pp. 1-7). IEEE.
Besharati, E., Naderan, M., & Namjoo, E. (2019). LR-HIDS: logistic regression host-based intrusion detection system for cloud environments. Journal of Ambient Intelligence and Humanized Computing, 10, 3669-3692.
Azam, Z., Islam, M. M., & Huda, M. N. (2023). Comparative analysis of intrusion detection systems and machine learning based model analysis through decision tree. IEEE Access.
Chapagain, P., Timalsina, A., Bhandari, M., & Chitrakar, R. (2022, January). Intrusion detection based on PCA with improved K-means. In International Conference on Electrical and Electronics Engineering (pp. 13-27). Singapore: Springer Singapore.
Lee, J., & Park, K. (2021). GAN-based imbalanced data intrusion detection system. Personal and Ubiquitous Computing, 25, 121-128.
Navya, V. K., Adithi, J., Rudrawal, D., Tailor, H., & James, N. (2021, October). Intrusion Detection System using Deep Neural Networks (DNN). In 2021 International Conference on Advancements in Electrical, Electronics, Communication, Computing and Automation (ICAECA) (pp. 1-6). IEEE.
Li, L. H., Ahmad, R., Tsai, W. C., & Sharma, A. K. (2021, January). A feature selection based dnn for intrusion detection system. In 2021 15th International Conference on Ubiquitous Information Management and Communication (IMCOM) (pp. 1-8). IEEE.
Kim, J., Kim, J., Kim, H., Shim, M., & Choi, E. (2020). CNN-based network intrusion detection against denial-of-service attacks. Electronics, 9(6), 916.
Chaibi, N., Atmani, B., & Mokaddem, M. (2020, October). Deep learning approaches to intrusion detection: A new performance of ANN and RNN on NSL-KDD. In Proceedings of the 1st International Conference on Intelligent Systems and Pattern Recognition (pp. 45-49).
Boukhalfa, A., Abdellaoui, A., Hmina, N., & Chaoui, H. (2020). LSTM deep learning method for network intrusion detection system. International Journal of Electrical and Computer Engineering, 10(3), 3315.
Hossain, M. D., Inoue, H., Ochiai, H., Fall, D., & Kadobayashi, Y. (2020). LSTM-based intrusion detection system for in-vehicle can bus communications. IEEE Access, 8, 185489-185502.
Sun, P., Liu, P., Li, Q., Liu, C., Lu, X., Hao, R., & Chen, J. (2020). DL-IDS: Extracting features using CNN-LSTM hybrid network for intrusion detection system. Security and communication networks, 2020, 1-11.
Yin, Chuanlong, Yuefei Zhu, Jinlong Fei, & Xinzheng He. (2017). "A deep learning approach for intrusion detection using recurrent neural networks." Ieee Access 5, pp. 21954-21961.
Xu, W., Jang-Jaccard, J., Singh, A., Wei, Y., & Sabrina, F. (2021). Improving performance of autoencoder-based network anomaly detection on nsl-kdd dataset. IEEE Access, 9, 140136-140146.
Ahsan, Mostofa, & Kendall E. Nygard. (2020)."Convolutional Neural Networks with LSTM for Intrusion Detection." In CATA, pp. 69-79.
Hassan, Mohammad Mehedi, Abdu Gumaei, Ahmed Alsanad, Majed Alrubaian, and Giancarlo Fortino. (2020)."A hybrid deep learning model for efficient intrusion detection in big data environment." Information Sciences 513, pp. 386-396.
Riyaz, & Sannasi Ganapathy. (2020). "A deep learning approach for effective intrusion detection in wireless networks using CNN." Soft Computing 24, pp. 17265-17278.
Yao, Ruizhe, Ning Wang, Zhihui Liu, Peng Chen, and Xianjun Sheng. (2021)."Intrusion Detection System in the Advanced Metering Infrastructure: A Cross-Layer FeatureFusion CNN-LSTM-Based Approach." Sensors 21, no. 2.
Sun, Pengfei, Pengju Liu, Qi Li, Chenxi Liu, Xiangling Lu, Ruochen Hao, & Jinpeng Chen. (2020)."DL-IDS: Extracting features using CNN-LSTM hybrid network for intrusion detection system." Security and Communication Networks.
Zhong, Ming, Yajin Zhou, & Gang Chen. (2021). "Sequential Model Based Intrusion Detection System for IoT Servers Using Deep Learning Methods." Sensors 21, no. 4: 1113.
Zhiqiang, Liu, Lin Zhijun, Gong Ting, & Shi Yucheng. (2021)."A Three-Layer Architecture for Intelligent Intrusion Detection Using Deep Learning." In Proceedings of Fifth International Congress on Information and Communication Technology, pp. 245- 255. Springer, Singapore.
Heidari, A., & Jabraeil Jamali, M. A. (2023). Internet of Things intrusion detection systems: A comprehensive review and future directions. Cluster Computing, 26(6), 3753-3780.
Maroosi, A., Zabbah, E., & Ataei Khabbaz, H. (2020). Network Intrusion Detection using a combination of artificial neural networks in a hierarchical manner. Electronic and Cyber Defense, 8(1), 89-99.
Meftah, S., Rachidi, T. & Assem, N. (2019). “Network Based Intrusion Detection Using the UNSW-NB15 Dataset,” International Journal of Computing and Digital Systems, vol. 8, pp. 477-487.
Zou, L., Luo, X., Zhang, Y., Yang, X., & Wang, X. (2023). HC-DTTSVM: A Network Intrusion Detection Method Based on Decision Tree Twin Support Vector Machine and Hierarchical Clustering. IEEE Access, 11, 21404-21416.
Nadoomi, M. A., & Sina, M. (2020). Using Ant Colony Algorithm and Pairwise Learning to Classify Attack in Intrusion Detection Systems. Journal of Communication Engineering, 9(36), 39-53.
Halim, Z., Yousaf, M. N., Waqas, M., Sulaiman, M., Abbas, G., HusIn, M., ... & Hanif, M. (2021). An effective genetic algorithm-based feature selection method for intrusion detection systems. Computers & Security, 110, 102448.
Wazirali, R. (2021). Intrusion detection system using fknn and improved PSO. CMC-Comput Mater Contin, 67(2), 1429-1445.
Heidari, A., Navimipour, N. J., & Unal, M. (2023). A Secure Intrusion Detection Platform Using Blockchain and Radial Basis Function Neural Networks for Internet of Drones. IEEE Internet of Things Journal.
Slamet, Mohamed, I. I., & Samsuri, F. (2020). Campus hybrid intrusion detection system using snort and c4. 5 algorithm. In InECCE2019: Proceedings of the 5th International Conference on Electrical, Control & Computer Engineering, Kuantan, Pahang, Malaysia, 29th July 2019 (pp. 591-603). Springer Singapore.
Thaseen, I. S. & Kumar, C. A. (2016). "Intrusion Detection Model using fusion of chi-square feature selection and multi class SVM," Journal of King Saud University-Computer and Information Sciences.
Almiani, M., AbuGhazleh, A., Al‐Rahayfeh, A., & Razaque, A. (2020). Cascaded hybrid intrusion detection model based on SOM and RBF neural networks. Concurrency and Computation: Practice and Experience, 32(21), e5233.
Chapagain, P., Timalsina, A., Bhandari, M., & Chitrakar, R. (2022, January). Intrusion detection based on PCA with improved K-means. In International Conference on Electrical and Electronics Engineering (pp. 13-27). Singapore: Springer Singapore.
Xu, J., Han, D., Li, K. C., & Jiang, H. (2020). A K-means algorithm based on characteristics of density applied to network intrusion detection. Computer Science and Information Systems, 17(2), 665-687.
Al-Haija, Q .A. & Zein-Sabatto, S. (2020). “An efficient deeplearning-based detection and classification system for cyberattacks in IoT communication networks,” Electronics, vol. 9, pp. 2152-2178.
Pradeep Mohan Kumar, K., Saravanan, M., Thenmozhi, M., & Vijayakumar, K. (2021). Intrusion detection system based on GA‐fuzzy classifier for detecting malicious attacks. Concurrency and Computation: Practice and Experience, 33(3), e5242.
Hassan Nataj Solhdar M. (2021). Using Of Neuro-Fuzzy Classifier for Intrusion Detection Systems. C4I Journal; 5 (2) :47-61
Roopak, M., Tian, G.Y., & Chambers, J. (2019). “Deep learning models for cyber security in IoT networks,” in 2019 IEEE 9th annual computing and communication workshop and conference (CCWC), pp. 452-457.
Ahmad, I., Basheri, M., Iqbal, M. J., & Rahim, A. (2018). Performance comparison of support vector machine, random forest, and extreme learning machine for intrusion detection. IEEE access, 6, 33789-33795.
Malhotra, H., & Sharma, P. (2019). Intrusion Detection using Machine Learning and Feature Selection. International Journal of Computer Network & Information Security, 11(4).
Belavagi, M. C., & Muniyal, B. (2016). Performance evaluation of supervised machine learning algorithms for intrusion detection. Procedia Computer Science, 89, 117-123.
Taher, K. A., Jisan, B. M. Y., & Rahman, M. M. (2019, January). Network intrusion detection using supervised machine learning technique with feature selection. In 2019 International Conference on Robotics, Electrical and Signal Processing Techniques (ICREST) (pp. 643-646). IEEE.
El Mourabit, Y., Bouirden, A., Toumanari, A., & Moussaid, N. E. (2015). Intrusion detection techniques in wireless sensor network using data mining algorithms: comparative evaluation based on attacks detection. International Journal of Advanced Computer Science and Applications, 6(9), 164-172.
Li, Y., Xia, J., Zhang, S., Yan, J., Ai, X., & Dai, K. (2012). An efficient intrusion detection system based on support vector machines and gradually feature removal method. Expert systems with applications, 39(1), 424-430.
Shah, B., & Trivedi, B. H. (2015, February). Reducing features of KDD CUP 1999 dataset for anomaly detection using back propagation neural network. In 2015 Fifth International Conference on Advanced Computing & Communication Technologies (pp. 247-251). IEEE.
Yulianto, A., Sukarno, P., & Suwastika, N. A. (2019, March). Improving Adaboost-based intrusion detection system (IDS) performance on CIC IDS 2017 dataset. In Journal of Physics: Conference Series (Vol. 1192, No. 1, p. 012018). IOP Publishing.
Abdulhammed, R., Faezipour, M., Musafer, H., & Abuzneid, A. (2019, June). Efficient network intrusion detection using pca-based dimensionality reduction of features. In 2019 International Symposium on Networks, Computers and Communications (ISNCC) (pp. 1-6). IEEE.
Pelletier, Z., & Abualkibash, M. (2020). Evaluating the CIC IDS-2017 Dataset Using Machine Learning Methods and Creating Multiple Predictive Models in the Statistical Computing Language R. Science, 5(2), 187-191.
Hammad, M., El-medany, W., & Ismail, Y. (2020, December). Intrusion Detection System using Feature Selection With Clustering and Classification Machine Learning Algorithms on the UNSW-NB15 dataset. In 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies (3ICT) (pp. 1-6). IEEE.
Faker, O., & Dogdu, E. (2019, April). Intrusion detection using big data and deep learning techniques. In Proceedings of the 2019 ACM Southeast Conference (pp. 86-93).
Ghajari, Ghazal, Ashutosh Ghimire, Elaheh Ghajari, & Fathi Amsaad. (2025). "Network Anomaly Detection for IoT Using Hyperdimensional Computing on NSL-KDD." arXiv preprint arXiv: 2503.03031.
Ghajari, G., Ghajari, E., Mohammadi, H., & Amsaad, F. (2025). Intrusion Detection in IoT Networks Using Hyperdimensional Computing: A Case Study on the NSL-KDD Dataset. arXiv preprint arXiv:2503.03037.
Hegde, R., Likitha, S., & Natesh, M. (2024, November). Intrusion Detection System Using Machine Learning Based on NSL KDD Dataset. In 2024 International Conference on Recent Advances in Science and Engineering Technology (ICRASET) (pp. 1-5). IEEE.
Araujo, I., Natalino, C., & Cardoso, D. (2021). A GPU-assisted NFV framework for intrusion detection system. Computer Communications, 169, 92-98..
Khandelwal, S., Wadhwa, E., & Shreejith, S. (2022, July). Deep learning-based embedded intrusion detection system for automotive can. In 2022 IEEE 33rd international conference on application-specific systems, architectures and processors (ASAP) (pp. 88-92). IEEE.
Le, T. T. H., Kim, H., Kang, H., & Kim, H. (2022). Classification and explanation for intrusion detection system based on ensemble trees and SHAP method. Sensors, 22(3), 1154.
پورخسروانی,صدرا , حیدران داروقه امنیه,زهرا , حسین زاده هرویان,مهدی و ذباح,ایمان . (1404). مروری بر سیستمهای تشخیص نفوذ در شبکه با استفاده از مدلهای مبتنی بر یادگیری ماشین. علوم رایانشی, 10(2), 83-102. doi: 10.22034/csj.2025.227853
MLA
پورخسروانی,صدرا , , حیدران داروقه امنیه,زهرا , , حسین زاده هرویان,مهدی , و ذباح,ایمان . "مروری بر سیستمهای تشخیص نفوذ در شبکه با استفاده از مدلهای مبتنی بر یادگیری ماشین", علوم رایانشی, 10, 2, 1404, 83-102. doi: 10.22034/csj.2025.227853
HARVARD
پورخسروانی صدرا, حیدران داروقه امنیه زهرا, حسین زاده هرویان مهدی, ذباح ایمان. (1404). 'مروری بر سیستمهای تشخیص نفوذ در شبکه با استفاده از مدلهای مبتنی بر یادگیری ماشین', علوم رایانشی, 10(2), pp. 83-102. doi: 10.22034/csj.2025.227853
CHICAGO
صدرا پورخسروانی, زهرا حیدران داروقه امنیه, مهدی حسین زاده هرویان و ایمان ذباح, "مروری بر سیستمهای تشخیص نفوذ در شبکه با استفاده از مدلهای مبتنی بر یادگیری ماشین," علوم رایانشی, 10 2 (1404): 83-102, doi: 10.22034/csj.2025.227853
VANCOUVER
پورخسروانی صدرا, حیدران داروقه امنیه زهرا, حسین زاده هرویان مهدی, ذباح ایمان. مروری بر سیستمهای تشخیص نفوذ در شبکه با استفاده از مدلهای مبتنی بر یادگیری ماشین. علوم رایانشی. 1404;10(2):83-102. doi: 10.22034/csj.2025.227853