Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection System

03/10/2022
by   Tuan-Hong Chua, et al.
0

Cybersecurity has become one of the focuses of organisations. The number of cyberattacks keeps increasing as Internet usage continues to grow. An intrusion detection system (IDS) is an alarm system that helps to detect cyberattacks. As new types of cyberattacks continue to emerge, researchers focus on developing machine learning (ML) based IDS to detect zero-day attacks. Researchers usually remove some or all attack samples from the training dataset and only include them in the testing dataset when evaluating the performance of an IDS on detecting zero-day attacks. Although this method may show the ability of an IDs to detect unknown attacks; however, it does not reflect the long-term performance of the IDS as it only shows the changes in the type of attacks. In this paper, we focus on evaluating the long-term performance of ML based IDS. To achieve this goal, we propose evaluating the ML-based IDS using a dataset that is created later than the training dataset. The proposed method can better assess the long-term performance of an ML-based IDS, as the testing dataset reflects the changes in the type of attack and the changes in network infrastructure over time. We have implemented six of the most popular ML models that are used for IDS, including decision tree (DT), random forest (RF), support vector machine (SVM), naïve Bayes (NB), artificial neural network (ANN) and deep neural network (DNN). Our experiments using the CIC-IDS2017 and the CSE-CIC-IDS2018 datasets show that SVM and ANN are most resistant to overfitting. Besides that, our experiment results also show that DT and RF suffer the most from overfitting, although they perform well on the training dataset. On the other hand, our experiments using the LUFlow dataset have shown that all models can perform well when the difference between the training and testing datasets is small.

READ FULL TEXT

page 18

page 19

page 20

page 25

page 26

page 27

research
05/09/2019

Evaluation of Machine Learning Classifiers for Zero-Day Intrusion Detection -- An Analysis on CIC-AWS-2018 dataset

Detecting Zero-Day intrusions has been the goal of Cybersecurity, especi...
research
01/10/2021

An Experimental Analysis of Attack Classification Using Machine Learning in IoT Networks

In recent years, there has been a massive increase in the amount of Inte...
research
01/09/2018

Fusion of ANN and SVM Classifiers for Network Attack Detection

With the progressive increase of network application and electronic devi...
research
03/08/2023

Forecasting the movements of Bitcoin prices: an application of machine learning algorithms

Cryptocurrencies, such as Bitcoin, are one of the most controversial and...
research
10/10/2018

LIRS: Enabling efficient machine learning on NVM-based storage via a lightweight implementation of random shuffling

Machine learning algorithms, such as Support Vector Machine (SVM) and De...
research
04/04/2022

Highly efficient reliability analysis of anisotropic heterogeneous slopes: Machine Learning aided Monte Carlo method

Machine Learning (ML) algorithms are increasingly used as surrogate mode...
research
03/01/2020

1D CNN Based Network Intrusion Detection with Normalization on Imbalanced Data

Intrusion detection system (IDS) plays an essential role in computer net...

Please sign up or login with your details

Forgot password? Click here to reset