Improved minority attack detection in Intrusion Detection System using efficient feature selection algorithms

Author:

Rejimol Robinson R. R.1ORCID,Anagha Madhav K. P.2,Thomas Ciza3ORCID

Affiliation:

1. Computer Science and Engineering SCT College of Engineering Thiruvananthapuram Kerala India

2. Engineering ITI Limited Bangalore India

3. School of Computer Science and Technology Karunya Institute of Technology and Sciences Coimbatore Tamil Nadu India

Abstract

AbstractMachine Learning and Data Mining algorithms are used extensively to enhance the performance of Intrusion Detection Systems. The number of training instances and the dimensionality of data are crucial factors affecting the performance of the model built during the training of any supervised learning algorithms. A sufficient proportion of instances having relevant features from all classes of attacks and normal traffic are considered most desirable while building the classification model that classifies the network traffic into attack and normal. This paper proposes a methodology to improve the accuracy of the model by giving importance to the relevant features that can contribute to model building. The feature selection using correlation‐based and information gain‐based techniques during training and testing contributes much to the detection of stealthier attacks and minority attacks. Then the features of the less detected attacks are identified as the second phase of the filter that is used to improve the performance. The relevant features of stealthy attacks are identified based on the correlation of corresponding features of the attack and normal data as the attacks are made stealthy mostly by making it resemble the normal traffic. Finally, the attacks that are rarely found in the training data are oversampled to improve their detection. CICIDS 2017 data set is employed as it comprises stealthier attacks generated using modern tools. NSL KDD data set is also used for evaluation to compare the proposed work with existing literature as it is used in most of the available literature. The results show superior performance with an accuracy of 99.8%, false positive rate of 0.2%, and a detection rate and 99.8%.

Publisher

Wiley

Reference39 articles.

1. Comparative study of selected data mining algorithms used for intrusion detection;Adebowale A.;International Journal of Soft Computing and Engineering (IJSCE),2013

2. Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model

3. Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm

4. Amrita M. A.(2013).Performance analysis of different feature selection methods in intrusion detection.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3