What Does Normal Even Mean? Evaluating Benign Traffic in Intrusion Detection Datasets

📅 2025-09-11
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Conventional intrusion detection systems label all benign traffic as a single class, introducing semantic ambiguity that obscures inherent structural heterogeneity. Method: To investigate whether benign traffic exhibits distinguishable fine-grained substructure, we apply unsupervised clustering algorithms—including HDBSCAN and Mean Shift—to benign samples from NSL-KDD, UNSW-NB15, and CIC-IDS2017. Contribution/Results: Empirical analysis reveals statistically significant and stable clustering patterns across all datasets, confirming intrinsic semantic heterogeneity within benign traffic. We thus propose a novel paradigm—“fine-grained partitioning of benign traffic”—which challenges the long-standing single-class labeling assumption. Subsequent experiments demonstrate that classifiers trained with multi-subclass benign labels—derived from the discovered structure—achieve improved attack-type discrimination and enhanced overall multiclass classification performance, particularly in distinguishing subtle or zero-day attacks. This work establishes a foundation for semantically aware benign modeling in intrusion detection.

Technology Category

Application Category

📝 Abstract
Supervised machine learning techniques rely on labeled data to achieve high task performance, but this requires the labels to capture some meaningful differences in the underlying data structure. For training network intrusion detection algorithms, most datasets contain a series of attack classes and a single large benign class which captures all non-attack network traffic. A review of intrusion detection papers and guides that explicitly state their data preprocessing steps identified that the majority took the labeled categories of the dataset at face value when training their algorithms. The present paper evaluates the structure of benign traffic in several common intrusion detection datasets (NSL-KDD, UNSW-NB15, and CIC-IDS 2017) and determines whether there are meaningful sub-categories within this traffic which may improve overall multi-classification performance using common machine learning techniques. We present an overview of some unsupervised clustering techniques (e.g., HDBSCAN, Mean Shift Clustering) and show how they differentially cluster the benign traffic space.
Problem

Research questions and friction points this paper is trying to address.

Evaluating meaningful sub-categories within benign network traffic
Assessing structure of benign traffic in intrusion detection datasets
Improving multi-classification performance using clustering techniques
Innovation

Methods, ideas, or system contributions that make the work stand out.

Unsupervised clustering techniques for traffic analysis
Evaluating benign traffic sub-categories in datasets
HDBSCAN and Mean Shift for improved classification
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Meghan Wilkinson
Mount Holyoake College, South Hadley, USA
R
Robert H. Thomson
Cognitive Security Institute