{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:47:38Z","timestamp":1784735258569,"version":"3.55.0"},"reference-count":36,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2022,6,10]],"date-time":"2022-06-10T00:00:00Z","timestamp":1654819200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001691","name":"JSPS KAKENHI","doi-asserted-by":"publisher","award":["JP20K11810"],"award-info":[{"award-number":["JP20K11810"]}],"id":[{"id":"10.13039\/501100001691","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001691","name":"JSPS KAKENHI","doi-asserted-by":"publisher","award":["JPJ000254"],"award-info":[{"award-number":["JPJ000254"]}],"id":[{"id":"10.13039\/501100001691","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the Ministry of Internal Affairs and Communications, Japan","award":["JP20K11810"],"award-info":[{"award-number":["JP20K11810"]}]},{"name":"the Ministry of Internal Affairs and Communications, Japan","award":["JPJ000254"],"award-info":[{"award-number":["JPJ000254"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With the growing diversity of cyberattacks in recent years, anomaly-based intrusion detection systems that can detect unknown attacks have attracted significant attention. Furthermore, a wide range of studies on anomaly detection using machine learning and deep learning methods have been conducted. However, many machine learning and deep learning-based methods require significant effort to design the detection feature values, extract the feature values from network packets, and acquire the labeled data used for model training. To solve the aforementioned problems, this paper proposes a new model called DOC-IDS, which is an intrusion detection system based on Perera\u2019s deep one-class classification. The DOC-IDS, which comprises a pair of one-dimensional convolutional neural networks and an autoencoder, uses three different loss functions for training. Although, in general, only regular traffic from the computer network subject to detection is used for anomaly detection training, the DOC-IDS also uses multi-class labeled traffic from open datasets for feature extraction. Therefore, by streamlining the classification task on multi-class labeled traffic, we can obtain a feature representation with highly enhanced data discrimination abilities. Simultaneously, we perform variance minimization in the feature space, even on regular traffic, to further improve the model\u2019s ability to discriminate between normal and abnormal traffic. The DOC-IDS is a single deep learning model that can automatically perform feature extraction and anomaly detection. This paper also reports experiments for evaluating the anomaly detection performance of the DOC-IDS. The results suggest that the DOC-IDS offers higher anomaly detection performance while reducing the load resulting from the design and extraction of feature values.<\/jats:p>","DOI":"10.3390\/s22124405","type":"journal-article","created":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T02:01:44Z","timestamp":1655085704000},"page":"4405","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["DOC-IDS: A Deep Learning-Based Method for Feature Extraction and Anomaly Detection in Network Traffic"],"prefix":"10.3390","volume":"22","author":[{"given":"Naoto","family":"Yoshimura","sequence":"first","affiliation":[{"name":"Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2686-2541","authenticated-orcid":false,"given":"Hiroki","family":"Kuzuno","sequence":"additional","affiliation":[{"name":"Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8970-9408","authenticated-orcid":false,"given":"Yoshiaki","family":"Shiraishi","sequence":"additional","affiliation":[{"name":"Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7942-5914","authenticated-orcid":false,"given":"Masakatu","family":"Morii","sequence":"additional","affiliation":[{"name":"Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Chalapathy, R., and Chawla, S. (2019). Deep learning for anomaly detection: A survey. arXiv.","DOI":"10.1145\/3394486.3406704"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","article-title":"A survey of network anomaly detection techniques","volume":"60","author":"Ahmed","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"949","DOI":"10.1007\/s10586-017-1117-8","article-title":"A survey of deep learning-based network anomaly detection","volume":"22","author":"Kwon","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"504","DOI":"10.1126\/science.1127647","article-title":"Reducing the dimensionality of data with neural networks","volume":"313","author":"Hinton","year":"2006","journal-title":"Science"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Mirsky, Y., Doitshman, T., Elovici, Y., and Shabtai, A. (2018, January 18\u201321). Kitsune: An ensemble of autoencoders for online network intrusion detection. Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS 2018), San Diego, CA, USA.","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"30387","DOI":"10.1109\/ACCESS.2020.2973023","article-title":"An unsupervised deep learning model for early network traffic anomaly","volume":"8","author":"Hwang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"108346","DOI":"10.1109\/ACCESS.2020.3001350","article-title":"Anomaly-based intrusion detection from network flow features using variational autoencoder","volume":"8","author":"Zavrak","year":"2020","journal-title":"IEEE Access"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"4184196","DOI":"10.1155\/2017\/4184196","article-title":"Network intrusion detection through stacking dilated convolutional autoencoders","volume":"2017","author":"Yu","year":"2017","journal-title":"Secur. Commun. Netw."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Vinayakumar, R., Soman, K.P., and Poornachandran, P. (2017, January 13\u201316). Applying convolutional neural network for network intrusion detection. Proceedings of the 2017 International Conference on Advances in Computing, Communications and Informatics (ICACCI 2017), Udupi, India.","DOI":"10.1109\/ICACCI.2017.8126009"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"108117","DOI":"10.1016\/j.comnet.2021.108117","article-title":"PBCNN: Packet bytes-based convolutional neural network for network intrusion detection","volume":"194","author":"Yu","year":"2021","journal-title":"Comput. Netw."},{"key":"ref_11","unstructured":"Wang, W., Zhu, M., Zeng, X.W., Ye, X.Z., and Sheng, Y.Q. (2017, January 11\u201313). Malware traffic classification using convolutional neural network for representation learning. Proceedings of the 2017 31st International Conference on Information Networking (ICOIN 2017), Da Nang, Vetnam."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"5450","DOI":"10.1109\/TIP.2019.2917862","article-title":"Learning deep features for one-class classification","volume":"28","author":"Perera","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE symposium on computational intelligence for security and defense applications (CISDA 2009), Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy 2018 (ICISSP 2018), Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Khan, M.A. (2021). HCRNNIDS: Hybrid convolutional recurrent neural network-based network intrusion detection system. Processes, 9.","DOI":"10.3390\/pr9050834"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"29575","DOI":"10.1109\/ACCESS.2020.2972627","article-title":"BAT: Learning methods on network intrusion detection using NSL-KDD Dataset","volume":"8","author":"Su","year":"2020","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"G\u00fcl, A., and Adal\u0131, E. (2017, January 5\u20137). Feature selection algorithm for IDS. Proceedings of the 2017 International Conference on Computer Science and Engineering (UBMK), Antalya, Turkey.","DOI":"10.1109\/UBMK.2017.8093538"},{"key":"ref_18","first-page":"548","article-title":"Implementation-oriented feature selection in UNSW-NB15 Intrusion Detection Dataset","volume":"418","author":"Alani","year":"2021","journal-title":"Intell. Syst. Des. Appl."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Gharaee, H., and Hosseinvand, H. (2016, January 27\u201328). A new feature selection ids based on genetic algorithm and SVM. Proceedings of the 2016 8th International Symposium on Telecommunications (IST), Tehran, Iran.","DOI":"10.1109\/ISTEL.2016.7881798"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"9731","DOI":"10.1007\/s00500-021-05893-0","article-title":"Machine learning and deep learning methods for intrusion detection systems: Recent developments and challenges","volume":"25","author":"Kocher","year":"2021","journal-title":"Soft Comput."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1443","DOI":"10.1162\/089976601750264965","article-title":"Estimating the support of a high-dimensional distribution","volume":"13","author":"Scholkopf","year":"2001","journal-title":"Neural Comput."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1023\/B:MACH.0000008084.60811.49","article-title":"Support vector data description","volume":"54","author":"Tax","year":"2004","journal-title":"Mach. Learn."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"861","DOI":"10.21105\/joss.00861","article-title":"UMAP: Uniform manifold approximation and projection","volume":"3","author":"McInnes","year":"2018","journal-title":"J. Open Source Softw."},{"key":"ref_24","unstructured":"Stratosphere (2022, February 25). Stratosphere Laboratory Datasets. Available online: https:\/\/www.stratosphereips.org\/datasets-overview."},{"key":"ref_25","unstructured":"KEYSIGHT (2022, February 25). Network Visibility and Network Test Products. Available online: https:\/\/www.keysight.com\/jp\/ja\/cmp\/2020\/network-visibility-network-test.html."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Draper-Gil, G., Lashkari, A.H., Mamun, M.S.I., and Ghorbani, A.A. (2016, January 19\u201321). Characterization of encrypted and VPN traffic using time-related features. Proceedings of the 2nd International Conference on Information Systems Security and Privacy 2016 (ICISSP 2016), Rome, Italy.","DOI":"10.5220\/0005740704070414"},{"key":"ref_27","unstructured":"(2022, February 25). Wireshark Go Deep. Available online: https:\/\/www.wireshark.org."},{"key":"ref_28","unstructured":"OpenVPN (2022, February 25). Business VPN|Next-Gen VPN|OpenVPN. Available online: https:\/\/openvpn.net\/."},{"key":"ref_29","unstructured":"FileZilla (2022, February 25). FileZilla\u2014The Free FTP Solution. Available online: https:\/\/filezilla-project.org\/."},{"key":"ref_30","unstructured":"Lashkari, A.H., Gil, G.D., Mamun, M.S.I., and Ghorbani, A.A. (2017, January 19\u201321). Characterization of Tor traffic using time based features. Proceedings of the 3rd International Conference on Information Systems Security and Privacy 2017 (ICISSP 2017), Porto, Portugal."},{"key":"ref_31","unstructured":"Whonix (2022, February 25). Whonix\u2122\u2014Software That Can Anonymize Everything You Do Online. Available online: https:\/\/www.whonix.org\/."},{"key":"ref_32","unstructured":"Takata, Y., Terada, M., Matsuki, T., Kasama, T., Araki, S., and Hatada, M. (2018). Datasets for Anti-Malware Research~MWS Datasets 2018~. IPSJ SIG Technical Reports 2018, Information Processing Society of Japan."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Jaiswal, A., Babu, A.R., Zadeh, M.Z., Banerjee, D., and Makedon, F. (2021). A Survey on contrastive self-supervised learning. Technologies, 9.","DOI":"10.3390\/technologies9010002"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","article-title":"ImageNet large scale visual recognition challenge","volume":"115","author":"Russakovsky","year":"2015","journal-title":"Int. J. Comput. Vis."},{"key":"ref_35","first-page":"9912","article-title":"Unsupervised learning of visual features by contrasting cluster assignments","volume":"33","author":"Caron","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_36","unstructured":"Biondi, P. (2022, February 25). The Scapy Community. Available online: https:\/\/scapy.net\/."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/12\/4405\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:27:49Z","timestamp":1760138869000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/12\/4405"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,10]]},"references-count":36,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["s22124405"],"URL":"https:\/\/doi.org\/10.3390\/s22124405","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,10]]}}}