<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Drift-based approach for evolving data stream classification in Intrusion detection system</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sugandh Seth</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gurwinder Singh</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kuljit Kaur Chahal</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Guru Nanak Dev University</institution>
          ,
          <addr-line>Amritsar</addr-line>
          ,
          <country country="IN">India</country>
        </aff>
      </contrib-group>
      <fpage>23</fpage>
      <lpage>30</lpage>
      <abstract>
        <p>Machine learning, and deep learning are extensively used to augment the performance of Intrusion detection systems. While the existing work on intrusion detection system using data mining and machine learning is efficient, but it involves training static batch classifiers to detect intrusions irrespective of the regular data stream's time-varying characteristics. Aims: This paper proposes an adaptive approach for online intrusion detection using stream-oriented learning for adapting to concept drift in real world environment. Method: Adaptive Random Forest classifier with ADWIN change detector is used for detecting change in a data stream and adapting to drift detection in the streamed data resulting in agile adaptation against unknown intrusions and the proposed approach also overcomes the need to retrain the model with time. Results: The latest CIC-IDS 2018 dataset is used for evaluating the approach. With the proposed method, the final Accuracy obtained is 99.5 % and a recall rate of 99.8%.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Intrusion Detection System</kwd>
        <kwd>Concept Drift</kwd>
        <kwd>Stream oriented learning</kwd>
        <kwd>Adaptive Random Forest</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Data mining and machine learning application’s prominence is increasing with time. Recently much
research is being proposed to utilize machine learning and deep learning techniques in many domains
such as weather forecasting, Spam detection, detecting fraudulent financial transactions, Intrusion
detection system etc. Traditionally, machine learning was primarily focused on using static data enough
to represent underlying distribution. However, usually, real-world problems don’t fit in models with
such restrictions. Also, many real-world applications such as Intrusion Detection Systems have
nonstationary data distributions that cause the problem of non-stationary learning or concept drift over the
time. Many studies with good results are available to investigate IDS (Intrusion Detection Systems)
using deep learning and machine learning approaches. However, most of the studies have deployed
static data sources. These studies fail to take rapid technological developments, and the problem of
concept drift into account [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], leading to poor performance of the system.
      </p>
      <p>As an indicator, concept drift holds importance due to its ability to measure time-based data
distribution variance. Besides, IDS can also be considered as a typical scenario of concept drift. Usually,
for a single source providing a data stream to a network, the data under the scanner is in a stable state,
distributed identically. And in case of an unknown intrusion, the current data distribution undergoes
dynamic changes as compared to the historical data. This motivates for building and adaptive Intrusion
detection method that involves incremental learning based on Concept Drift that quickly adapts to new
intrusion types.</p>
      <p>
        Moreover, the endless emergence of new attacks and security loopholes raises the need for an ideal
classifier that quickly adapts to intrusion's emerging methods. In such a situation, the static batch
learning approach discussed above delivers poor performance. In other words, when a static classifier
goes obsolete, its response to new intrusion types becomes slow, and a re-training [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] becomes
mandatory that needs high-cost investments. Contrarily, incremental learning with the adaptive
updating of the classifier to a regular data stream over time ensures the promising performance of an
IDS.
      </p>
      <sec id="sec-1-1">
        <title>Thus, current IDS models have numerous noteworthy drawbacks.</title>
        <p> The underlying model of current IDS usually detects only known network attacks whereas IDS
are prone to novel malicious attacks.
 The IDS models are built on static data. Whereas data come in streams in an IDS, and the data
distribution may vary over the time.
 IDS models become obsolete with time and needs to be retrained which is cost intensive.</p>
        <p>
          To overcome the above research gaps, we propose a concept drift-based approach for evolving data
stream classification in Intrusion detection system. With limited processing and memory time, the
concept drift detection method ensures accurate and quick identification of changes in the underlying
data point distribution, followed by the fastest possible adaptation in the model [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
      </sec>
      <sec id="sec-1-2">
        <title>The major contributions of the paper are as follows:</title>
        <p> High performance intrusion detection system based on streamed data with concept drift.
 Incremental IDS model with adaptive updation of classification models, achieving high
accuracy in real time.</p>
        <p> IDS with agile adaptation against unknown intrusions.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>Lot of research is done in the field of intrusion detection. Many researchers have proposed machine
and deep learning techniques for detecting intrusions.</p>
      <p>
        Ferrag et al. in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] evaluated seven deep learning techniques namely: Deep neural network(DNN),
recurrent neural network(RNN), restricted Boltzmann machine(RBM), deep belied networks(DBN),
recurrent neural network, convolutional neural network(CNN), deep Boltzmann machine(DBM) and
Deep Autoencoders(DA) on the latest CIC-IDS 2018 dataset. Though this paper has comprehensively
evaluated the deep learning techniques, but all the evaluation is done on the static data.
      </p>
      <p>
        (Karatas et al. in [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] evaluated six machine learning-based IDS using K Nearest Neighbour, Random
Forest, Gradient Boosting, Adaboost, Decision Tree, and Linear Discriminant Analysis algorithm on
the CIC-IDS 2018 dataset. This proposed approach focuses on balancing the skewed dataset using
oversampling with SMOTE. Though this approach gives good results, but it is also on static data.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] Roshan et al. proposed an adaptive Intrusion detection system based on extreme learning an
clustering. The proposed model was evaluated using the NSL-KDD dataset and have claimed to achieve
an accuracy rate of 89% for novel attacks.
      </p>
      <p>
        Feng et al. in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]developed a plug and play to capture the packets. Deep learning techniques were
used for detecting DOS attacks, CNN was used to detect XSS and LSTM was used for detecting SQL
Injection.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] Yuan et al.proposed concept drift-based ensemble incremental approach for intrusion detection
system. The HDDM drift detection method based on Hoeffding’s bounds was used to detect the
anomaly and the ensemble based incremental learning using weighted voting was used for
classification. All the experiments were done on the NSL-KDD dataset. They claimed to have achieved
an accuracy of 94.91 % with the proposed approach. In [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] Breve &amp; Zhao,proposed semi supervised
classification with concept drift for intrusion detection. The study is based on passive drift detection
without explicitly using any algorithm and is inspired by the competitive and cooperative behavior of
some animals to protect their territory. It is based on natural way of learning new data and forgetting
the older ones. The proposed algorithm evaluated on the KDD Cup 1999 dataset.
      </p>
      <p>
        Park et al. in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] proposed online eigenvector transformation for reflecting concept drift detection in
Intrusion Detection System. In Online PCA eigenvectors were computed by converting the existing
eigenvector as per the latest data without generating a new eigenvector. They compared the
performance of network intrusion detection using both online and offline PCA. Both the methods gave
good precision rate but the recall rate for online PCA outperformed the offline method.
      </p>
      <p>The majority of the proposed work in literature is on old datasets or is based on static datasets. To
overcome the above research gaps, In this paper Adaptive Random forest classifier with drift detection
to classify attacks in stream data using the latest CIC-IDS 2018 dataset.</p>
      <p>The rest of the paper is structured as follows. Section 2 reviews the current literature Intrusion
detection systems. Section 3 discusses the research methodology. Section 4 discusses the results
obtained. Section 5 concludes the paper with a summary.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Research Methodology</title>
      <p>In the network security domain, malicious intrusions have increased, making the IDS (Intrusion
Detection System) design vital for securer systems. Recently, machine learning methods are
increasingly used for network abnormality detection. However, currently available works do not explore
the variation in data over the time, restricting their ability to detect new intrusion types. Therefore, for
unpredicted changes in the status data's statistical properties over time, we propose an IDS with a
concept drift-based incremental learning using adaptive random forest classifier with adwin drift
detection.</p>
    </sec>
    <sec id="sec-4">
      <title>3.1. Data Preprocessing</title>
    </sec>
    <sec id="sec-5">
      <title>3.1.1. Data Collection</title>
      <p>The proposed study is done on the latest CIC IDS 2018 dataset. The CIC IDS 2018 is a massive
dataset that incorporates 14 modern-day attacks. The CIC IDS dataset was published by
Communications Security Establishment (CSE) &amp; the Canadian Institute for Cybersecurity (CIC). The
dataset comprises of 80 features with 16 million rows.</p>
    </sec>
    <sec id="sec-6">
      <title>3.1.2. Data Transformation</title>
      <p>Dos attacks-Slowloris
FTP-BruteForce
Infiltration
Sql Injection</p>
      <p>The CIC-IDS dataset comprises of 13 modern-day attacks as listed in the table 1. The dataset is
relabeled to Attack and Benign sessions. All the 13 attack types listed in the table are relabeled to attack
class. Thus, the problem of multi classification of attacks is reduced to binary classification. Thus, the
dataset mix after preprocessing is listed in table 2.</p>
    </sec>
    <sec id="sec-7">
      <title>3.2. Training the Model</title>
      <p>Any modification in the underlying process of data generation is referred to as concept drift. In the
classification context, concept drift points to variation in the target variable’s statistical properties. The
target variable is the one the model is trying to make a time-based prediction for, and the term concept
is used for the quantity the researcher aims to predict. As previously mentioned, the distribution that
creates the data stream’s items can change with time. To address this problem of concept drift in
Intrusion Detection System the proposed model uses Adaptive Random Forest with Adaptive
Windowing method for concept drift detection (ADWIN).</p>
      <sec id="sec-7-1">
        <title>Adaptive Random Forest</title>
        <p>
          Random Forest is a popular learning algorithm in regression and non-stream classification (batch)
tasks. This approach creates multiple trees, avoiding overfitting of the branches through bootstrap
aggregation for decorrelation [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] and random feature selection when nodes split. For creating each
tree’s bootstraps, the original Random Forest passes over the input data multiple times. It also passes
over a part of the original features for each of the tree’s internal nodes.
        </p>
        <p>Performing multiple passes becomes infeasible when using data stream learning with input data.
Thus, Random Forests need to adapt to the streaming data based on:

</p>
        <p>A suitable process for online bootstrap aggregation</p>
        <p>Limitation of each leaf split decision into a feature subset</p>
        <p>
          To achieve the second requirement, the algorithm for the base tree is modified [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. For effective
modification, the set of features to be taken for further splits is limited to a random subset of m size.
Here, m&lt;M with M is the total feature count. For non-streaming bagging, random samples are drawn
by replacing the training set to create bootstrap samples (size Z) that are then used to train each of the
n base models. An original training instance can be found K times in every bootstrap sample, with P
(K=k) following a binomial distribution. Binomial distribution for instances with higher Z values
adheres to a Poisson distribution (λ=1). Adaptive Random Forests, uses Poisson (λ=6) instead of (λ=1)
as in leveraging bagging [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]. This uses resampling, causing a practical impact of increasing the chances
of higher weight assignment to instances while the base models are trained.
        </p>
        <p>However, when working with Adaptive algorithms, the primary aim is to deal with data streams that
evolve over time. Thus, including other strategies it is also essential to cope with the problem of concept
drifts. Adaptive Random Forest deploy a permissive threshold in ARF for warning detection instead of
a tree reset process on drift detection. Alongside, background trees are created and trained along with
the ensemble without influencing its predictions. However, on the detection of a drift a background tree
is used to replace the originating tree for the warning signal.</p>
        <p>Thus, three major features of Adaptive Random Forest are as follows:
1. Increasing the variance with resampling
2. Increasing the variance with random selection of feature subsets for node splits based on
hoeffding tree
3. Drift detection per base tree</p>
      </sec>
      <sec id="sec-7-2">
        <title>Adwin Drift Detection</title>
        <p>
          Adaptive Random Forest algorithm uses ADWIN (Adaptive Windowing) for drift detection.
ADWIN [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] is a sliding window algorithm to detect drifts in a data stream. This algorithm is based on
keeping statistics of a variable sized window to detect concept drift. The window size is computed by
cutting the statistics widows at various points and comparing the average of various statistic measure
over different windows. A drift is detected if the difference between the average statistics is above a
certain threshold value. The proposed model uses adaptive random forest with adwin drift detection to
adapt the model to concept drift in streams over the time. The results of the proposed model is discussed
in section 4.
        </p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>4. Results and Discussions</title>
      <p>In this study, the performance of the adaptive Random Forest algorithm is evaluated. on the latest
CIC-IDS 2018 dataset. The proposed system was implemented using scikit-multiflow library in python.
All the experiments were performed on AWS cloud platform using the configuration in Table 4.</p>
      <p>
        The proposed model is evaluated on various performance metrics - Accuracy, Precision, Kappa,
Recall, F- Measure. The performance metrics [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] can be evaluated using the following equations(1-5)
=


=
+ 

+ 
+ 
+
      </p>
      <sec id="sec-8-1">
        <title>Accuracy is the percentage of samples that were correctly classified. Recall is the ratio of samples correctly classified as attack among all attack samples. Kappa = (total accuracy – random accuracy) / (1- random accuracy)</title>
        <p>(1)
(2)
(3)
The coefficient of kappa calculates an agreement between the values of classification and truth value.
A kappa value of 1 stands for perfect agreement, while a value of 0 does not stand for agreement.
(4)
(5)

=</p>
        <p>1 
= 2 ∗


+ 
∗ 
+ 
Precision is the ratio of correctly classified samples as attacks with total samples graded as attacks.</p>
      </sec>
      <sec id="sec-8-2">
        <title>The F1 Score is the harmonic mean of recall and Accuracy.</title>
        <p>Besides Accuracy other performance evaluation parameters such as Precision, F-Measure, Kappa
and Recall metrics are also important to evaluate the performance of the system. Analysis of result using
the above performance metrics with other adaptive algorithms is listed in Table.</p>
        <p>The CIC-IDS 2018 dataset is converted into a data stream and holdout evaluation method is used for
evaluating the performance of the model. The holdout evaluation method updates the statistics of
incoming samples without evaluating the performance or predicting the labels. The performance of the
model is evaluated after every n samples. The evaluation is done on the unseen test samples and the test
sets are dynamically generated from the data stream.</p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>4.1. Analysis of Results of the proposed method in Comparison to other</title>
    </sec>
    <sec id="sec-10">
      <title>Adaptive Learning Algorithms on Stream Data</title>
    </sec>
    <sec id="sec-11">
      <title>4.2 Analysis of Results of the proposed method in Comparison to other</title>
    </sec>
    <sec id="sec-12">
      <title>Learning Algorithms on Stream Data</title>
      <p>KNN
0.9158</p>
    </sec>
    <sec id="sec-13">
      <title>4.3 Analysis of Results of the proposed method in Comparison to other</title>
    </sec>
    <sec id="sec-14">
      <title>Machine and Deep learning algorithm on static data.</title>
    </sec>
    <sec id="sec-15">
      <title>5. Conclusion</title>
      <p>ARF(Proposed)
99.5
RBM</p>
      <p>Most of the applications based on streaming data need a fast response, requiring re(training) of an
algorithm with the latest data available. Most of the existing Artificial Intelligence based IDS models
are trained on static data. Whereas data come in streams in an IDS, and the data distribution may vary
over the time since attack patterns tend to evolve over the time resulting in a concept drift. Moreover,
for the IDS to work efficiently it needs to adapt itself to be able to detect new attack classes over the
time. In such scenarios the static data models performs poorly since static batch learning models get
outdated and needs to be updated with time. To overcome the above challenges, this paper uses adaptive
random forest classifier with ADWIN drift detector for building concept drift-based model for evolving
data stream classification in Intrusion detection system. The proposed algorithm outperforms other
approaches in literature with high accuracy, precision and recall rate of 99.5 %, 99.9% and 99.8%
respectively.</p>
    </sec>
    <sec id="sec-16">
      <title>6. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Xu</surname>
          </string-name>
          , R., Cheng, Y.,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Xie</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Yang</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Improved Long Short-Term Memory based anomaly detection with concept drift adaptive method for supporting IoT services</article-title>
          .
          <source>Future Generation Computer Systems</source>
          ,
          <volume>112</volume>
          ,
          <fpage>228</fpage>
          -
          <lpage>242</lpage>
          . https://doi.org/10.1016/j.future.
          <year>2020</year>
          .
          <volume>05</volume>
          .035
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Folino</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pisani</surname>
            ,
            <given-names>F. S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Pontieri</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>A GP-based ensemble classification framework for time-changing streams of intrusion detection data</article-title>
          .
          <source>Soft Computing</source>
          ,
          <volume>24</volume>
          (
          <issue>23</issue>
          ),
          <fpage>17541</fpage>
          -
          <lpage>17560</lpage>
          . https://doi.org/10.1007/s00500-020-05200-3
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Breve</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Zhao</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Semi-supervised Learning with Concept Drift Using Particle Dynamics Applied to Network Intrusion Detection Data</article-title>
          .
          <source>2013 BRICS Congress on Computational Intelligence and 11th Brazilian Congress on Computational Intelligence</source>
          . https://doi.org/10.1109/
          <string-name>
            <surname>BRICS-CCI-CBIC</surname>
          </string-name>
          .
          <year>2013</year>
          .63
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Ferrag</surname>
            ,
            <given-names>M. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maglaras</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Moschoyiannis</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Janicke</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study</article-title>
          .
          <source>Journal of Information Security and Applications</source>
          ,
          <volume>50</volume>
          , 102419. https://doi.org/10.1016/j.jisa.
          <year>2019</year>
          .102419
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Karatas</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Demir</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sahingoz</surname>
            ,
            <given-names>O. K.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Increasing the Performance of Machine LearningBased IDSs on an Imbalanced and Up-to-Date Dataset</article-title>
          .
          <source>IEEE Access</source>
          ,
          <volume>8</volume>
          ,
          <fpage>32150</fpage>
          -
          <lpage>32162</lpage>
          . https://doi.org/10.1109/access.
          <year>2020</year>
          .2973219
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Roshan</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Miche</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Akusok</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lendasse</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>Adaptive and online network intrusion detection system using clustering and Extreme Learning Machines</article-title>
          .
          <source>Journal of the Franklin Institute</source>
          ,
          <volume>355</volume>
          (
          <issue>4</issue>
          ),
          <fpage>1752</fpage>
          -
          <lpage>1779</lpage>
          . https://doi.org/10.1016/j.jfranklin.
          <year>2017</year>
          .
          <volume>06</volume>
          .006
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Feng</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yong</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhou</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Zhou</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>Anomaly detection in ad-hoc networks based on deep learning model: A plug and play device</article-title>
          .
          <source>Ad Hoc Networks</source>
          ,
          <volume>84</volume>
          ,
          <fpage>82</fpage>
          -
          <lpage>89</lpage>
          . https://doi.org/10.1016/j.adhoc.
          <year>2018</year>
          .
          <volume>09</volume>
          .014
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Yuan</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhuang</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhu</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Hao</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>A Concept Drift Based Ensemble Incremental Learning Approach for Intrusion Detection</article-title>
          . 2018
          <string-name>
            <given-names>IEEE</given-names>
            <surname>International</surname>
          </string-name>
          <article-title>Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and</article-title>
          IEEE Cyber,
          <article-title>Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData</article-title>
          ),
          <fpage>350</fpage>
          -
          <lpage>357</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Park</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Seo</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jeong</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Kim</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>Online eigenvector transformation reflecting concept drift for improving network intrusion detection</article-title>
          .
          <source>Expert Systems</source>
          ,
          <volume>37</volume>
          (
          <issue>5</issue>
          ), 1. https://doi.org/10.1111/exsy.12477
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Breiman</surname>
            <given-names>L. Random</given-names>
          </string-name>
          <string-name>
            <surname>Forests</surname>
          </string-name>
          .
          <source>Machine Learning</source>
          .
          <year>2001</year>
          ;
          <volume>45</volume>
          :
          <fpage>5</fpage>
          -
          <lpage>32</lpage>
          . Available from: https://doi.org/10.1023/a:1010933404324
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Gomes</surname>
            ,
            <given-names>H. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bifet</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Read</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barddal</surname>
            ,
            <given-names>J. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Enembreck</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pfharinger</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Holmes</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Abdessalem</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>Adaptive random forests for evolving data stream classification</article-title>
          .
          <source>Machine Learning</source>
          ,
          <volume>106</volume>
          (
          <fpage>9</fpage>
          -
          <lpage>10</lpage>
          ),
          <fpage>1469</fpage>
          -
          <lpage>1495</lpage>
          . https://doi.org/10.1007/s10994-017-5642-8
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Bifet</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Holmes</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kirkby</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Pfahringer</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>Moa: Massive online analysis</article-title>
          .
          <source>The Journal of Machine Learning Research</source>
          ,
          <volume>11</volume>
          ,
          <fpage>1601</fpage>
          -
          <lpage>1604</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Bifet</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Gavaldà</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Learning from Time-Changing Data with Adaptive Windowing</article-title>
          .
          <source>Proceedings of the Seventh SIAM International Conference on Data Mining, April 26-28</source>
          ,
          <year>2007</year>
          , Minneapolis, Minnesota, USA. https://doi.org/10.1137/1.9781611972771.42
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Shone</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ngoc</surname>
            ,
            <given-names>T. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Phai</surname>
            ,
            <given-names>V. D.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Shi</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>A Deep Learning Approach to Network Intrusion Detection</article-title>
          .
          <source>IEEE Transactions on Emerging Topics in Computational Intelligence</source>
          ,
          <volume>2</volume>
          (
          <issue>1</issue>
          ),
          <fpage>41</fpage>
          -
          <lpage>50</lpage>
          . https://doi.org/10.1109/tetci.
          <year>2017</year>
          .2772792
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>