Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection Using Progressive Dataset

被引:5
作者
Chua, Tuan-Hong [1 ]
Salam, Iftekhar [1 ]
机构
[1] Xiamen Univ Malaysia, Sch Comp & Data Sci, Sepang 43900, Malaysia
来源
SYMMETRY-BASEL | 2023年 / 15卷 / 06期
关键词
intrusion detection; machine learning; deep learning; cybersecurity; DETECTION SYSTEM;
D O I
10.3390/sym15061251
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Cybersecurity has become one of the focuses of organisations. The number of cyberattacks keeps increasing as Internet usage continues to grow. As new types of cyberattacks continue to emerge, researchers focus on developing machine learning (ML)-based intrusion detection systems (IDS) to detect zero-day attacks. They usually remove some or all attack samples from the training dataset and only include them in the testing dataset when evaluating the performance. This method may detect unknown attacks; however, it does not reflect the long-term performance of the IDS as it only shows the changes in the type of attacks. In this work, we focused on evaluating the long-term performance of ML-based IDS. To achieve this goal, we proposed evaluating the ML-based IDS using a dataset created later than the training dataset. The proposed method can better assess the long-term performance as the testing dataset reflects the changes in the attack type and network infrastructure changes over time. We have implemented six of the most popular ML models, including decision tree (DT), random forest (RF), support vector machine (SVM), naive Bayes (NB), artificial neural network (ANN), and deep neural network (DNN). These models are trained and tested with a pair of datasets with symmetrical classes. Our experiments using the CIC-IDS2017 and the CSE-CIC-IDS2018 datasets show that SVM and ANN are most resistant to overfitting. Our experiments also indicate that DT and RF suffer the most from overfitting, although they perform well on the training dataset. On the other hand, our experiments using the LUFlow dataset have shown that all models can perform well when the difference between the training and testing datasets is small.
引用
收藏
页数:31
相关论文
共 50 条
  • [1] Comparative Evaluation of Network-Based Intrusion Detection: Deep Learning vs Traditional Machine Learning Approach
    Udurume, Miracle
    Shakhov, Vladimir
    Koo, Insoo
    2024 FIFTEENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS, ICUFN 2024, 2024, : 520 - 525
  • [2] Comparative Evaluation of Machine Learning Algorithms for Network Intrusion Detection and Attack Classification
    Leon, Miguel
    Markovic, Tijana
    Punnekkat, Sasikumar
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [3] Intrusion detection and prevention with machine learning algorithms
    Chang, Victor
    Boddu, Sreeja
    Xu, Qianwen Ariel
    Doan, Le Minh Thao
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2023, 14 (06) : 617 - 631
  • [4] A Comparative Study of Using Boosting-Based Machine Learning Algorithms for IoT Network Intrusion Detection
    Mohamed Saied
    Shawkat Guirguis
    Magda Madbouly
    International Journal of Computational Intelligence Systems, 16
  • [5] A Comparative Study of Using Boosting-Based Machine Learning Algorithms for IoT Network Intrusion Detection
    Saied, Mohamed
    Guirguis, Shawkat
    Madbouly, Magda
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)
  • [6] Performance Evaluation of Supervised Machine Learning Algorithms for Intrusion Detection
    Belavagi, Manjula C.
    Muniyal, Balachandra
    TWELFTH INTERNATIONAL CONFERENCE ON COMMUNICATION NETWORKS, ICCN 2016 / TWELFTH INTERNATIONAL CONFERENCE ON DATA MINING AND WAREHOUSING, ICDMW 2016 / TWELFTH INTERNATIONAL CONFERENCE ON IMAGE AND SIGNAL PROCESSING, ICISP 2016, 2016, 89 : 117 - 123
  • [7] On the Evaluation of Sequential Machine Learning for Network Intrusion Detection
    Corsini, Andrea
    Yang, Shanchieh Jay
    Apruzzese, Giovanni
    ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [8] Intrusion Detection System for CAN Bus In-Vehicle Network based on Machine Learning Algorithms
    Alfardus, Asma
    Rawat, Danda B.
    2021 IEEE 12TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2021, : 944 - 949
  • [9] Dataset of attacks on a live enterprise VoIP network for machine learning based intrusion detection and prevention systems
    Alvares, Christabelle
    Dinesh, Dristi
    Alvi, Syed
    Gautam, Tannish
    Hasib, Maheen
    Raza, Ali
    COMPUTER NETWORKS, 2021, 197
  • [10] Enhancing Network Intrusion Detection Model Using Machine Learning Algorithms
    Awad, Nancy Awadallah
    CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 67 (01): : 979 - 990