An approach for optimizing ensemble intrusion detection systems

Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key t...

Full description

Bibliographic Details
Main Authors: Stiawan, D., Heryanto, A., Bardadi, A., Rini, D. P., Subroto, I. M., Kurniabudi, K., Idris, M. Y.
Format: Article
Language:English
Published: Institute of Electrical and Electronics Engineers Inc. 2021
Subjects:
Online Access:http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf
_version_ 1796865827816865792
author Stiawan, D.
Heryanto, A.
Bardadi, A.
Rini, D. P.
Subroto, I. M.
Kurniabudi, K.
Idris, M. Y.
author_facet Stiawan, D.
Heryanto, A.
Bardadi, A.
Rini, D. P.
Subroto, I. M.
Kurniabudi, K.
Idris, M. Y.
author_sort Stiawan, D.
collection ePrints
description Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key to improve the performance of intrusion detection system. This study aims to find the best relevant selected features that can be used as important features in a new IDS dataset. To achieve the aim, an approach for generating optimized ensemble IDS is developed. Six features selection methods are used and compared, i.e.: Information Gain (IG), Gain Ratio (GR), Symmetrical Uncertainty (SU), Relief-F (R-F), One-R (OR) and Chi-Square (CS). The feature selection techniques produce sets of selected features. Each best selected number of features that are obtained from feature ranking step for respective feature selection technique will be used to classify attacks via four classification methods, i.e.: Bayesian Network (BN), Naïve Bayesian (NB), Decision Tree: J48 and SOM. Then, each feature selection technique with its respective best features is combined with each classifier method to generate ensemble IDSs. Lastly, the ensemble IDSs are evaluated using Hold-up, K-fold validation approaches, as well as F-Measure and statistical validation approaches. Experimental results using Weka tools on ITD-UTM dataset show the optimized ensemble IDSs using (SU and BN); using (CS and BN) or (CS and SOM) or (IG and NB); and using (OR and BN) with respective ten, four and seven best selected features achieves 81.0316%, 85.2593%, and 80.8625% of accuracy, respectively. In addition, ensemble IDSs using (SU and BN) and using (OR and J48) with ten and six best respective selected features, perform the best F-measure value, i.e.: 0.853 and 0.830, respectively. Indirect comparison with other ensemble IDS on different dataset is discussed.
first_indexed 2024-03-05T21:03:01Z
format Article
id utm.eprints-94464
institution Universiti Teknologi Malaysia - ePrints
language English
last_indexed 2024-03-05T21:03:01Z
publishDate 2021
publisher Institute of Electrical and Electronics Engineers Inc.
record_format dspace
spelling utm.eprints-944642022-03-31T14:54:54Z http://eprints.utm.my/94464/ An approach for optimizing ensemble intrusion detection systems Stiawan, D. Heryanto, A. Bardadi, A. Rini, D. P. Subroto, I. M. Kurniabudi, K. Idris, M. Y. QA75 Electronic computers. Computer science Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key to improve the performance of intrusion detection system. This study aims to find the best relevant selected features that can be used as important features in a new IDS dataset. To achieve the aim, an approach for generating optimized ensemble IDS is developed. Six features selection methods are used and compared, i.e.: Information Gain (IG), Gain Ratio (GR), Symmetrical Uncertainty (SU), Relief-F (R-F), One-R (OR) and Chi-Square (CS). The feature selection techniques produce sets of selected features. Each best selected number of features that are obtained from feature ranking step for respective feature selection technique will be used to classify attacks via four classification methods, i.e.: Bayesian Network (BN), Naïve Bayesian (NB), Decision Tree: J48 and SOM. Then, each feature selection technique with its respective best features is combined with each classifier method to generate ensemble IDSs. Lastly, the ensemble IDSs are evaluated using Hold-up, K-fold validation approaches, as well as F-Measure and statistical validation approaches. Experimental results using Weka tools on ITD-UTM dataset show the optimized ensemble IDSs using (SU and BN); using (CS and BN) or (CS and SOM) or (IG and NB); and using (OR and BN) with respective ten, four and seven best selected features achieves 81.0316%, 85.2593%, and 80.8625% of accuracy, respectively. In addition, ensemble IDSs using (SU and BN) and using (OR and J48) with ten and six best respective selected features, perform the best F-measure value, i.e.: 0.853 and 0.830, respectively. Indirect comparison with other ensemble IDS on different dataset is discussed. Institute of Electrical and Electronics Engineers Inc. 2021 Article PeerReviewed application/pdf en http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf Stiawan, D. and Heryanto, A. and Bardadi, A. and Rini, D. P. and Subroto, I. M. and Kurniabudi, K. and Idris, M. Y. (2021) An approach for optimizing ensemble intrusion detection systems. IEEE Access, 9 . 6930- 6947. ISSN 2169-3536 http://dx.doi.org/10.1109/ACCESS.2020.3046246 DOI: 10.1109/ACCESS.2020.3046246
spellingShingle QA75 Electronic computers. Computer science
Stiawan, D.
Heryanto, A.
Bardadi, A.
Rini, D. P.
Subroto, I. M.
Kurniabudi, K.
Idris, M. Y.
An approach for optimizing ensemble intrusion detection systems
title An approach for optimizing ensemble intrusion detection systems
title_full An approach for optimizing ensemble intrusion detection systems
title_fullStr An approach for optimizing ensemble intrusion detection systems
title_full_unstemmed An approach for optimizing ensemble intrusion detection systems
title_short An approach for optimizing ensemble intrusion detection systems
title_sort approach for optimizing ensemble intrusion detection systems
topic QA75 Electronic computers. Computer science
url http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf
work_keys_str_mv AT stiawand anapproachforoptimizingensembleintrusiondetectionsystems
AT heryantoa anapproachforoptimizingensembleintrusiondetectionsystems
AT bardadia anapproachforoptimizingensembleintrusiondetectionsystems
AT rinidp anapproachforoptimizingensembleintrusiondetectionsystems
AT subrotoim anapproachforoptimizingensembleintrusiondetectionsystems
AT kurniabudik anapproachforoptimizingensembleintrusiondetectionsystems
AT idrismy anapproachforoptimizingensembleintrusiondetectionsystems
AT stiawand approachforoptimizingensembleintrusiondetectionsystems
AT heryantoa approachforoptimizingensembleintrusiondetectionsystems
AT bardadia approachforoptimizingensembleintrusiondetectionsystems
AT rinidp approachforoptimizingensembleintrusiondetectionsystems
AT subrotoim approachforoptimizingensembleintrusiondetectionsystems
AT kurniabudik approachforoptimizingensembleintrusiondetectionsystems
AT idrismy approachforoptimizingensembleintrusiondetectionsystems