An empirical assessment of ensemble methods and traditional machine for web-based attack detection in 5.0

被引:22
作者
Chakir, Oumaima [1 ]
Rehaimi, Abdeslam [1 ]
Sadqi, Yassine [1 ]
Alaoui, El Arbi Abdellaoui [2 ]
Krichen, Moez [3 ,4 ]
Gaba, Gurjot Singh [5 ]
Gurtov, Andrei [5 ]
机构
[1] USMS Univ, FPBM, Lab LIMATI, Beni Mellal, Morocco
[2] Univ Moulay Ismail, Dept Sci, IMAGE Lab, ENS,IEVIA Team, Meknes, Morocco
[3] Al Baha Univ, Fac CSIT, Al Bahah, Saudi Arabia
[4] Univ Sfax, ReDCAD Lab, Sfax, Tunisia
[5] Linkoping Univ, Sch Comp & Informat Sci, Linkoping, Sweden
关键词
Cybersecurity; Ensemble methods; Industry; 5; 0; Machine learning; Web-based attack detection; INTRUSION DETECTION SYSTEMS; PROTOCOL;
D O I
10.1016/j.jksuci.2023.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity attacks that target software have become profitable and popular targets for cybercriminals who consciously take advantage of web-based vulnerabilities and execute attacks that might jeopardize essential industry 5.0 features. Several machine learning-based techniques have been developed in the literature to identify these types of assaults. In contrast to single classifiers, ensemble methods have not been evaluated empirically. To the best of our knowledge, this work is the first empirical evaluation of both homogeneous and heterogeneous ensemble approaches compared to single classifiers for web -based attack detection in industry 5.0, utilizing two of the most realistic public web-based attack data -sets. The authors divided the experiment into three main phases: In the first phase, they evaluated the performance of five well-established supervised machine learning (ML) classifiers. In the second phase, they constructed a heterogeneous ensemble of the three best-performing ML algorithms using max vot-ing and stacking methods. In the third phase, they used four well-known homogeneous ensembles to evaluate the performance of the bagging and boosting method. The results based on the ECML/PKDD 2007 and CSIC HTTP 2010 datasets revealed that bagging, particularly Random Forest, outperformed sin-gle classifiers in terms of accuracy, precision, F-value, FPR, and area of the ROC curve with values of 99.597%, 98.274%, 99.129%, 0.523%, 100 and 99.867%, 99.867%, 99.867%, 0.267%, 100, respectively. In con-trast, single classifiers performed better than boosting and stacking. However, in terms of FPR, the boost-ing exceeded single classifiers. Max voting is appropriate when accuracy, precision, and FPR are the primary concerns, whereas single classifiers can be employed when recall, FNR, training, and prediction times are critical elements. In terms of training time, ensemble approaches are more likely to be affected by data volume than single classifiers. The paper's findings will help security researchers and practition-ers identify the most efficient learning techniques for securing web applications. (c) 2023 The Author(s). Published by Elsevier B.V. on behalf of King Saud University. This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
引用
收藏
页码:103 / 119
页数:17
相关论文
共 70 条
  • [1] Inverse groundwater salinization modeling in a sandstone?s aquifer using stand-alone models with an improved non-linear ensemble machine learning technique
    Abba, S. I.
    Benaafi, Mohammed
    Usman, A. G.
    Aljundi, Isam H.
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 8162 - 8175
  • [2] A survey of intrusion detection systems based on ensemble and hybrid classifiers
    Aburomman, Abdulla Amin
    Reaz, Mamun Bin Ibne
    [J]. COMPUTERS & SECURITY, 2017, 65 : 135 - 152
  • [3] A novel SVM-kNN-PSO ensemble method for intrusion detection system
    Aburomman, Abdulla Amin
    Reaz, Mamun Bin Ibne
    [J]. APPLIED SOFT COMPUTING, 2016, 38 : 360 - 372
  • [4] Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)
    Adadi, Amina
    Berrada, Mohammed
    [J]. IEEE ACCESS, 2018, 6 : 52138 - 52160
  • [5] Deep Learning for Vulnerability and Attack Detection on Web Applications: A Systematic Literature Review
    Alaoui, Rokia Lamrani
    Nfaoui, El Habib
    [J]. FUTURE INTERNET, 2022, 14 (04):
  • [6] Effective and scalable black-box fuzzing approach for modern web applications
    Alsaedi, Aseel
    Alhuzali, Abeer
    Bamasag, Omaimah
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 10068 - 10078
  • [7] [Anonymous], WEB APPL ATTACKS DAT
  • [8] MapReduce based intelligent model for intrusion detection using machine learning technique
    Asif, Muhammad
    Abbas, Sagheer
    Khan, M. A.
    Fatima, Areej
    Khan, Muhammad Adnan
    Lee, Sang-Woong
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 9723 - 9731
  • [9] Belouch M., 2017, P ICC 17 2 INT C INT, P1, DOI [10.1145/3018896.3065830, DOI 10.1145/3018896.3065830]
  • [10] An enhanced deep learning based framework for web attacks detection, mitigation and attacker profiling
    Bin Shahid, Waleed
    Aslam, Baber
    Abbas, Haider
    Bin Khalid, Saad
    Afzal, Hammad
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 198