Temporal Analysis Framework for Intrusion Detection Systems: A Novel Taxonomy for Time-Aware Cybersecurity

📅 2025-11-05
📈 Citations: 0
✹ Influential: 0
📄 PDF

career value

197K/year
đŸ€– AI Summary
Existing network intrusion detection systems (IDS) predominantly focus on late-stage attack behaviors, hindering early threat identification and proactive defense. Method: This paper introduces the first time-aware NIDS analysis framework, establishing a novel taxonomy grounded in temporal dimensions—from static flow analysis to multi-window sequential modeling—and systematically reviewing 40+ recent studies via MITRE ATT&CK tactic mapping. Contribution/Results: We uncover a systematic bias in mainstream datasets toward post-compromise attack stages, limiting early detection. Empirical evaluation demonstrates that time-aware methods comprehensively cover all ATT&CK phases—from reconnaissance and resource development to impact—significantly enhancing detection capability at earlier stages. Our work establishes a theoretical foundation and an extensible temporal analysis paradigm for cross-phase, forward-looking defense.

Technology Category

Application Category

📝 Abstract
Most intrusion detection systems still identify attacks only after significant damage has occurred, detecting late-stage tactics rather than early indicators of compromise. This paper introduces a temporal analysis framework and taxonomy for time-aware network intrusion detection. Through a systematic review of over 40 studies published between 2020 and 2025, we classify NIDS methods according to their treatment of time, from static per-flow analysis to multi-window sequential modeling. The proposed taxonomy reveals that inter-flow sequential and temporal window-based methods provide the broadest temporal coverage across MITRE ATT&CK tactics, enabling detection from Reconnaissance through Impact stages. Our analysis further exposes systematic bias in widely used datasets, which emphasize late-stage attacks and thus limit progress toward early detection. This framework provides essential groundwork for developing IDS capable of anticipating rather than merely reacting to cyber threats, advancing the field toward truly proactive defense mechanisms.
Problem

Research questions and friction points this paper is trying to address.

Developing time-aware intrusion detection to identify early attack indicators
Classifying NIDS methods by temporal analysis from static to sequential modeling
Addressing dataset bias limiting progress toward proactive cyber threat detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Introduces temporal analysis framework for time-aware intrusion detection
Classifies NIDS methods by time treatment from static to sequential
Uses multi-window modeling for broad MITRE ATT&CK tactic coverage
T
Tatiana S. Parlanti
Universidad Nacional de Cuyo, Facultad de Ingeniería, Laboratorio de Sistemas Inteligentes (LABSIN), Centro Universitario, Mendoza, M5502JMA, Mendoza, Argentina; Consejo Nacional de Investigaciones Científicas y Técnicas (CONICET), Godoy Cruz 2290, C.A.B.A, C1425FQB, Buenos Aires, Argentina
C
C. A. Catania
Universidad Nacional de Cuyo, Facultad de Ingeniería, Laboratorio de Sistemas Inteligentes (LABSIN), Centro Universitario, Mendoza, M5502JMA, Mendoza, Argentina; Consejo Nacional de Investigaciones Científicas y Técnicas (CONICET), Godoy Cruz 2290, C.A.B.A, C1425FQB, Buenos Aires, Argentina