An approach for optimizing ensemble intrusion detection systems
Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key t...
Main Authors: | , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Institute of Electrical and Electronics Engineers Inc.
2021
|
Subjects: | |
Online Access: | http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf |
_version_ | 1796865827816865792 |
---|---|
author | Stiawan, D. Heryanto, A. Bardadi, A. Rini, D. P. Subroto, I. M. Kurniabudi, K. Idris, M. Y. |
author_facet | Stiawan, D. Heryanto, A. Bardadi, A. Rini, D. P. Subroto, I. M. Kurniabudi, K. Idris, M. Y. |
author_sort | Stiawan, D. |
collection | ePrints |
description | Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key to improve the performance of intrusion detection system. This study aims to find the best relevant selected features that can be used as important features in a new IDS dataset. To achieve the aim, an approach for generating optimized ensemble IDS is developed. Six features selection methods are used and compared, i.e.: Information Gain (IG), Gain Ratio (GR), Symmetrical Uncertainty (SU), Relief-F (R-F), One-R (OR) and Chi-Square (CS). The feature selection techniques produce sets of selected features. Each best selected number of features that are obtained from feature ranking step for respective feature selection technique will be used to classify attacks via four classification methods, i.e.: Bayesian Network (BN), Naïve Bayesian (NB), Decision Tree: J48 and SOM. Then, each feature selection technique with its respective best features is combined with each classifier method to generate ensemble IDSs. Lastly, the ensemble IDSs are evaluated using Hold-up, K-fold validation approaches, as well as F-Measure and statistical validation approaches. Experimental results using Weka tools on ITD-UTM dataset show the optimized ensemble IDSs using (SU and BN); using (CS and BN) or (CS and SOM) or (IG and NB); and using (OR and BN) with respective ten, four and seven best selected features achieves 81.0316%, 85.2593%, and 80.8625% of accuracy, respectively. In addition, ensemble IDSs using (SU and BN) and using (OR and J48) with ten and six best respective selected features, perform the best F-measure value, i.e.: 0.853 and 0.830, respectively. Indirect comparison with other ensemble IDS on different dataset is discussed. |
first_indexed | 2024-03-05T21:03:01Z |
format | Article |
id | utm.eprints-94464 |
institution | Universiti Teknologi Malaysia - ePrints |
language | English |
last_indexed | 2024-03-05T21:03:01Z |
publishDate | 2021 |
publisher | Institute of Electrical and Electronics Engineers Inc. |
record_format | dspace |
spelling | utm.eprints-944642022-03-31T14:54:54Z http://eprints.utm.my/94464/ An approach for optimizing ensemble intrusion detection systems Stiawan, D. Heryanto, A. Bardadi, A. Rini, D. P. Subroto, I. M. Kurniabudi, K. Idris, M. Y. QA75 Electronic computers. Computer science Intrusion Detection System is yet an interesting research topic. With a very large amount of traffic in real-time networks, feature selection techniques that are effectively able to find important and relevant features are required. Hence, the most important and relevant set of features is the key to improve the performance of intrusion detection system. This study aims to find the best relevant selected features that can be used as important features in a new IDS dataset. To achieve the aim, an approach for generating optimized ensemble IDS is developed. Six features selection methods are used and compared, i.e.: Information Gain (IG), Gain Ratio (GR), Symmetrical Uncertainty (SU), Relief-F (R-F), One-R (OR) and Chi-Square (CS). The feature selection techniques produce sets of selected features. Each best selected number of features that are obtained from feature ranking step for respective feature selection technique will be used to classify attacks via four classification methods, i.e.: Bayesian Network (BN), Naïve Bayesian (NB), Decision Tree: J48 and SOM. Then, each feature selection technique with its respective best features is combined with each classifier method to generate ensemble IDSs. Lastly, the ensemble IDSs are evaluated using Hold-up, K-fold validation approaches, as well as F-Measure and statistical validation approaches. Experimental results using Weka tools on ITD-UTM dataset show the optimized ensemble IDSs using (SU and BN); using (CS and BN) or (CS and SOM) or (IG and NB); and using (OR and BN) with respective ten, four and seven best selected features achieves 81.0316%, 85.2593%, and 80.8625% of accuracy, respectively. In addition, ensemble IDSs using (SU and BN) and using (OR and J48) with ten and six best respective selected features, perform the best F-measure value, i.e.: 0.853 and 0.830, respectively. Indirect comparison with other ensemble IDS on different dataset is discussed. Institute of Electrical and Electronics Engineers Inc. 2021 Article PeerReviewed application/pdf en http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf Stiawan, D. and Heryanto, A. and Bardadi, A. and Rini, D. P. and Subroto, I. M. and Kurniabudi, K. and Idris, M. Y. (2021) An approach for optimizing ensemble intrusion detection systems. IEEE Access, 9 . 6930- 6947. ISSN 2169-3536 http://dx.doi.org/10.1109/ACCESS.2020.3046246 DOI: 10.1109/ACCESS.2020.3046246 |
spellingShingle | QA75 Electronic computers. Computer science Stiawan, D. Heryanto, A. Bardadi, A. Rini, D. P. Subroto, I. M. Kurniabudi, K. Idris, M. Y. An approach for optimizing ensemble intrusion detection systems |
title | An approach for optimizing ensemble intrusion detection systems |
title_full | An approach for optimizing ensemble intrusion detection systems |
title_fullStr | An approach for optimizing ensemble intrusion detection systems |
title_full_unstemmed | An approach for optimizing ensemble intrusion detection systems |
title_short | An approach for optimizing ensemble intrusion detection systems |
title_sort | approach for optimizing ensemble intrusion detection systems |
topic | QA75 Electronic computers. Computer science |
url | http://eprints.utm.my/94464/1/MohdYazidIdris2021_AnApproachforOptimizingEnsembleIntrusion.pdf |
work_keys_str_mv | AT stiawand anapproachforoptimizingensembleintrusiondetectionsystems AT heryantoa anapproachforoptimizingensembleintrusiondetectionsystems AT bardadia anapproachforoptimizingensembleintrusiondetectionsystems AT rinidp anapproachforoptimizingensembleintrusiondetectionsystems AT subrotoim anapproachforoptimizingensembleintrusiondetectionsystems AT kurniabudik anapproachforoptimizingensembleintrusiondetectionsystems AT idrismy anapproachforoptimizingensembleintrusiondetectionsystems AT stiawand approachforoptimizingensembleintrusiondetectionsystems AT heryantoa approachforoptimizingensembleintrusiondetectionsystems AT bardadia approachforoptimizingensembleintrusiondetectionsystems AT rinidp approachforoptimizingensembleintrusiondetectionsystems AT subrotoim approachforoptimizingensembleintrusiondetectionsystems AT kurniabudik approachforoptimizingensembleintrusiondetectionsystems AT idrismy approachforoptimizingensembleintrusiondetectionsystems |