Anomaly-based intrusion detection system based on SMOTE-IPF, Whale Optimization Algorithm, and ensemble learning

被引:0
作者
Shana, Tibebu Bekele [1 ]
Kumari, Neetu [2 ]
Agarwal, Mayank [1 ]
Mondal, Samrat [1 ]
Rathnayake, Upaka [3 ]
机构
[1] Indian Inst Technol Patna, Dept Comp Sci & Engn, Patna 801103, Bihar, India
[2] Indian Inst Technol Patna, Dept Math, Patna 801103, Bihar, India
[3] Atlantic Technol Univ, Fac Engn & Design, Dept Civil Engn & Construct, Sligo F91 YW50, Ireland
来源
INTELLIGENT SYSTEMS WITH APPLICATIONS | 2025年 / 27卷
关键词
Network intrusion detection systems; Whale Optimization Algorithm; Machine learning; Features selection; Imbalanced data; Cyber security; SAMPLING METHOD; ATTACKS;
D O I
10.1016/j.iswa.2025.200543
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Nowadays, cybersecurity is a major worldwide problem. Intrusion detection systems (IDS) help guarantee network security by detecting malicious entries from legitimate entries in network traffic data. IDS has considerable potential for detecting dynamic cyber threats, identifying abnormalities, and identifying malicious conduct within the network. In this paper, we propose Machine Learning (ML) models with an emphasis on the Synthetic Minority Over-sampling Technique (SMOTE) with Iterative Partitioning Filter (IPF) for class imbalance and the Whale Optimization Algorithm (WOA) for feature selection. Class imbalance often results in poorly constructed ML models prioritizing the majority class. In addition, the absence of feature selection can lead to higher computational complexity without impacting performance accuracy. This study uses Bagging, AdaBoost, Extreme Gradient Boosting (XGBoost) and Extra Trees Classifier as classification models. The two widely used datasets to assess the proposed method are NLS-KDD and UNSW-NB15. The K-Fold cross-validation technique trains this model to minimize potential overfitting. These models are evaluated based on performance metrics such as accuracy, precision, recall, and F1-score. The experimental results demonstrate that the Extra Trees Classifier significantly outperforms the baseline models and achieves accuracy values of 99.9% for the NSL-KDD dataset and 97% for the UNSW-NB 15 dataset and outperforms all evaluation measures compared to baseline models for multi-classification of the IDS.
引用
收藏
页数:18
相关论文
共 91 条
[1]   Deep and Machine Learning Approaches for Anomaly-Based Intrusion Detection of Imbalanced Network Traffic [J].
Abdulhammed, Razan ;
Faezipour, Miad ;
Abuzneid, Abdelshakour ;
AbuMallouh, Arafat .
IEEE SENSORS LETTERS, 2019, 3 (01)
[2]  
Abidin Dodo Zaenal, 2020, 2020 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), P284, DOI 10.1109/ICIMCIS51567.2020.9354273
[3]   An improved PIO feature selection algorithm for IoT network intrusion detection system based on ensemble learning [J].
Abu Alghanam, Orieb ;
Almobaideen, Wesam ;
Saadeh, Maha ;
Adwan, Omar .
EXPERT SYSTEMS WITH APPLICATIONS, 2023, 213
[4]   Network intrusion detection using oversampling technique and machine learning algorithms [J].
Ahmed, Hafiza Anisa ;
Hameed, Anum ;
Bawany, Narmeen Zakaria .
PEERJ COMPUTER SCIENCE, 2022, 8 :1-19
[5]   Malware cyberattacks detection using a novel feature selection method based on a modified whale optimization algorithm [J].
Al Ogaili, Riyadh Rahef Nuiaa ;
Alomari, Esraa Saleh ;
Alkorani, Manar Bashar Mortatha ;
Alyasseri, Zaid Abdi Alkareem ;
Mohammed, Mazin Abed ;
Dhanaraj, Rajesh Kumar ;
Manickam, Selvakumar ;
Kadry, Seifedine ;
Anbar, Mohammed ;
Karuppayah, Shankar .
WIRELESS NETWORKS, 2024, 30 (09) :7257-7273
[6]   A new intrusion detection system based on using non-linear statistical analysis and features selection techniques [J].
Al-Bakaa, Aliaa ;
Al-Musawi, Bahaa .
COMPUTERS & SECURITY, 2022, 122
[7]   An efficient SVM based DEHO classifier to detect DDoS attack in cloud computing environment [J].
Alam, Gowthul M. M. ;
Kumar, Jerald Nirmal S. ;
Mageswari, Uma R. ;
Raj, Michael T. F. .
COMPUTER NETWORKS, 2022, 215
[8]  
Alazab Moutaz, 2022, Expert Systems With Applications, DOI [10.1016/j.eswa.2022.118439, 10.1016/j.eswa.2022.118439]
[9]   WS-AWRE: Intrusion Detection Using Optimized Whale Sine Feature Selection and Artificial Neural Network (ANN) Weighted Random Forest Classifier [J].
Aldabash, Omar Abdulkhaleq ;
Akay, Mehmet Fatih .
APPLIED SCIENCES-BASEL, 2024, 14 (05)
[10]   A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks [J].
Altunay, Hakan Can ;
Albayrak, Zafer .
ENGINEERING SCIENCE AND TECHNOLOGY-AN INTERNATIONAL JOURNAL-JESTECH, 2023, 38