Netinfo Security ›› 2024, Vol. 24 ›› Issue (12): 1819-1830.doi: 10.3969/j.issn.1671-1122.2024.12.002

Previous Articles     Next Articles

A Review of Incremental Intrusion Detection

JIN Zhigang(), CHEN Xuyang, WU Xiaodong, LIU Kai   

  1. School of Electrical and Information Engineering, Tianjin University, Tianjin 300072, China
  • Received:2024-08-10 Online:2024-12-10 Published:2025-01-10

Abstract:

Intrusion detection system is an important component of network defense framework which can monitor the network security situation and detect attacks in real time. However, the traditional intrusion detection systems are oriented to static networks, and it is hard to deal with new attack methods which are coming in all the time. Some researchers have begun to explore how to enable intrusion detection to have incremental capabilities, so that it can quickly update existing models for new types of attacks and learn new knowledge without consuming a lot of resources for retrain, in order to adapt to the complex network environment. This paper aims to summarize the recent research on incremental intrusion detection. Firstly, this paper introduced the basic concepts of incremental learning and intrusion detection, summarized commonly used datasets. Then this paper analyzed existing methods. Finally, this paper analyzed the problems existing in research results, and looked forward to the future development trends in this field.

Key words: intrusion detection, incremental learning, continual learning, cyber security

CLC Number: