MARATTO

article · Journal of Network and Systems Management

Deep Learning Based Hybrid Intrusion Detection Systems to Protect Satellite Networks

202369 citationsOpen accessBadr University in Cairo

In plain language

Integrating satellite and terrestrial networks provides advantages such as high throughput, low latency, and global coverage, but it also creates shared security challenges. To detect malicious traffic in these integrated environments, four hybrid intrusion detection architectures combine sequential forward feature selection using random forest with machine learning or deep learning classifiers, namely Random Forest, Long Short-Term Memory, Artificial Neural Networks, and Gated Recurrent Unit. Testing on simulated satellite and terrestrial datasets demonstrates that selecting key features improves computational efficiency and detection rates. On the satellite dataset, the feature-selected Random Forest model achieved 90.5 percent accuracy, whilst the Gated Recurrent Unit model led deep learning approaches with 87 percent accuracy using ten features. On the terrestrial dataset, the Random Forest and Gated Recurrent Unit systems attained 78.52 percent and 79 percent accuracy respectively.

Key takeaways

  • Four hybrid intrusion detection systems were developed using random forest feature selection combined with machine learning and deep learning models.
  • Feature selection using ten chosen attributes improved detection accuracy and computational efficiency across all tests.
  • On a simulated satellite network dataset, the hybrid random forest model achieved the highest overall accuracy at 90.5 percent.
  • Among deep learning approaches, the gated recurrent unit model performed best, reaching 87 percent accuracy on satellite data and 79 percent on terrestrial data.

Why it matters

As global communications increasingly link space and ground networks, vulnerabilities can spread between the two domains. Enhancing automated intrusion detection ensures that critical communication links remain secure against cyber threats. Using feature selection to reduce computational demands allows advanced artificial intelligence models to process network data more efficiently without sacrificing security performance.

Commercialisation angle

The proposed systems target security monitoring within satellite-terrestrial communication networks. Potential users include network operators managing combined space and ground communication infrastructure. The research remains at an early, experimental stage, as the models have been validated only on simulated satellite traffic and benchmark terrestrial datasets rather than live, operational infrastructure.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Abstract Despite the fact that satellite-terrestrial systems have advantages such as high throughput, low latency, and low energy consumption, as well as low exposure to physical threats and natural disasters and cost-effective global coverage, their integration exposes both of them to particular security challenges that can arise due to the migration of security challenges from one to another. Intrusion Detection Systems (IDS) can also be used to provide a high level of protection for modern network environments such as satellite-terrestrial integrated networks (STINs). To optimize the detection performance of malicious activities in network traffic, four hybrid intrusion detection systems for satellite-terrestrial communication systems (SAT-IDSs) are proposed in this paper. All the proposed systems exploit the sequential forward feature selection (SFS) method based on random forest (RF) to select important features from the dataset that increase relevance and reduce complexity and then combine them with a machine learning (ML) or deep learning (DL) model; Random Forest (RF), Long Short-Term memory (LSTM), Artificial Neural Networks (ANN), and Gated Recurrent Unit (GRU). Two datasets—STIN, which simulates satellite networks, and UNSW-NB15, which simulates terrestrial networks—were used to evaluate the performance of the proposed SAT-IDSs. The experimental results indicate that selecting significant and crucial features produced by RF-SFS vastly improves detection accuracy and computational efficiency. In the first dataset (STIN), the proposed hybrid ML system SFS-RF achieved an accuracy of 90.5% after using 10 selected features, compared to 85.41% when using the whole dataset. Furthermore, the RF-SFS-GRU model achieved the highest performance of the three proposed hybrid DL-based SAT-IDS with an accuracy of 87% after using 10 selected features, compared to 79% when using the entire dataset. In the second dataset (UNSW-NB15), the proposed hybrid ML system SFS-RF achieved an accuracy of 78.52% after using 10 selected features, compared to 75.4% when using the whole dataset. The model with the highest accuracy of the three proposed hybrid DL-based SAT-IDS was the RF-SFS-GRU model. It achieved an accuracy of 79% after using 10 selected features, compared to 74% when using the whole dataset.

Research topics

  • Network Security and Intrusion Detection
  • Anomaly Detection Techniques and Applications
  • Internet Traffic Analysis and Secure E-voting

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1007/s10922-023-09767-8

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.