A Double-Layered Hybrid Approach for Network Intrusion Detection System Using Combined Naive Bayes and SVM

被引:56
|
作者
Wisanwanichthan, Treepop [1 ]
Thammawichai, Mason [1 ]
机构
[1] Navaminda Kasatriyadhiraj Royal Air Force Acad, Bangkok 10220, Thailand
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Feature extraction; Support vector machines; Machine learning; Probes; Radio frequency; Principal component analysis; Correlation; Correlation feature selection; double-layered hybrid approach; machine learning; Naive Bayes; intrusion detection system; network security; NSL-KDD; SVM; DEEP LEARNING APPROACH; FEATURE-SELECTION; RANDOM FOREST; SECURITY APPROACH; DETECTION MODEL; MACHINE; CLASSIFIER; ALGORITHM; ENSEMBLE; COLONY;
D O I
10.1109/ACCESS.2021.3118573
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A pattern matching method (signature-based) is widely used in basic network intrusion detection systems (IDS). A more robust method is to use a machine learning classifier to detect anomalies and unseen attacks. However, a single machine learning classifier is unlikely to be able to accurately detect all types of attacks, especially uncommon attacks e.g., Remote2Local (R2L) and User2Root (U2R) due to a large difference in the patterns of attacks. Thus, a hybrid approach offers more promising performance. In this paper, we proposed a Double-Layered Hybrid Approach (DLHA) designed specifically to address the aforementioned problem. We studied common characteristics of different attack categories by creating Principal Component Analysis (PCA) variables that maximize variance from each attack type, and found that R2L and U2R attacks have similar behaviour to normal users. DLHA deploys Naive Bayes classifier as Layer 1 to detect DoS and Probe, and adopts SVM as Layer 2 to distinguish R2L and U2R from normal instances. We compared our work with other published research articles using the NSL-KDD data set. The experimental results suggest that DLHA outperforms several existing state-of-the-art IDS techniques, and is significantly better than any single machine learning classifier by large margins. DLHA also displays an outstanding performance in detecting rare attacks by obtaining a detection rate of 96.67% and 100% from R2L and U2R respectively.
引用
收藏
页码:138432 / 138450
页数:19
相关论文
共 50 条
  • [1] Layered Approach for Intrusion Detection Using Naive Bayes Classifier
    Sharma, Neelam
    Mukherjee, Saurabh
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 639 - 644
  • [2] An effective intrusion detection approach using SVM with naive Bayes feature embedding
    Gu, Jie
    Lu, Shan
    COMPUTERS & SECURITY, 2021, 103
  • [3] NETWORK INTRUSION DETECTION USING NAIVE BAYES
    Panda, Mrutyunjaya
    Patra, Manas Ranjan
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (12): : 258 - 263
  • [4] Intrusion Detection System using Naive Bayes algorithm
    Sharmila, B. S.
    Nagapadma, Rohini
    2019 5TH IEEE INTERNATIONAL WIE CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (WIECON-ECE 2019), 2019,
  • [5] The SVM and Layered Intrusion Detection System Based on Network Hierarchical
    Hu, Chao Ju
    Wang, Jin
    INTERNET OF THINGS-BK, 2012, 312 : 486 - 493
  • [6] Online Naive Bayes Classification for Network Intrusion Detection
    Gumus, Fatma
    Sakar, C. Okan
    Erdem, Zeki
    Kursun, Olcay
    2014 PROCEEDINGS OF THE IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM 2014), 2014, : 670 - 674
  • [7] A network intrusion detection system based on a Hidden Naive Bayes multiclass classifier
    Koc, Levent
    Mazzuchi, Thomas A.
    Sarkani, Shahram
    EXPERT SYSTEMS WITH APPLICATIONS, 2012, 39 (18) : 13492 - 13500
  • [8] Modified Naive Bayes Intrusion Detection System (MNBIDS)
    Bhosale, Karuna S.
    Nenova, Maria
    Iliev, Georgi
    PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON COMPUTATIONAL TECHNIQUES, ELECTRONICS AND MECHANICAL SYSTEMS (CTEMS), 2018, : 291 - 296
  • [9] Addressing Challenges for Intrusion Detection System using Naive Bayes and PCA Algorithm
    Almansob, Saqr Mohammed
    Lomte, Santosh Shivajirao
    2017 2ND INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2017, : 565 - 568
  • [10] Intrusion Detection using Naive Bayes Classifier with Feature Reduction
    Mukherjee, Saurabh
    Sharma, Neelam
    2ND INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION, CONTROL AND INFORMATION TECHNOLOGY (C3IT-2012), 2012, 4 : 119 - 128