A Double-Layered Hybrid Approach for Network Intrusion Detection System Using Combined Naive Bayes and SVM

被引:56
|
作者
Wisanwanichthan, Treepop [1 ]
Thammawichai, Mason [1 ]
机构
[1] Navaminda Kasatriyadhiraj Royal Air Force Acad, Bangkok 10220, Thailand
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Feature extraction; Support vector machines; Machine learning; Probes; Radio frequency; Principal component analysis; Correlation; Correlation feature selection; double-layered hybrid approach; machine learning; Naive Bayes; intrusion detection system; network security; NSL-KDD; SVM; DEEP LEARNING APPROACH; FEATURE-SELECTION; RANDOM FOREST; SECURITY APPROACH; DETECTION MODEL; MACHINE; CLASSIFIER; ALGORITHM; ENSEMBLE; COLONY;
D O I
10.1109/ACCESS.2021.3118573
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A pattern matching method (signature-based) is widely used in basic network intrusion detection systems (IDS). A more robust method is to use a machine learning classifier to detect anomalies and unseen attacks. However, a single machine learning classifier is unlikely to be able to accurately detect all types of attacks, especially uncommon attacks e.g., Remote2Local (R2L) and User2Root (U2R) due to a large difference in the patterns of attacks. Thus, a hybrid approach offers more promising performance. In this paper, we proposed a Double-Layered Hybrid Approach (DLHA) designed specifically to address the aforementioned problem. We studied common characteristics of different attack categories by creating Principal Component Analysis (PCA) variables that maximize variance from each attack type, and found that R2L and U2R attacks have similar behaviour to normal users. DLHA deploys Naive Bayes classifier as Layer 1 to detect DoS and Probe, and adopts SVM as Layer 2 to distinguish R2L and U2R from normal instances. We compared our work with other published research articles using the NSL-KDD data set. The experimental results suggest that DLHA outperforms several existing state-of-the-art IDS techniques, and is significantly better than any single machine learning classifier by large margins. DLHA also displays an outstanding performance in detecting rare attacks by obtaining a detection rate of 96.67% and 100% from R2L and U2R respectively.
引用
收藏
页码:138432 / 138450
页数:19
相关论文
共 50 条
  • [21] Network intrusion Detection for Medical Information System using SVM Optimized by ICSA
    Chen, Xiao
    Song, Wenhui
    WIENER KLINISCHE WOCHENSCHRIFT, 2024, 136 : S463 - S464
  • [22] Drought Prediction Using SVM, Naive Bayes and LSTM Recurrent Neural Network
    Li, Kaimin
    Yang, Bing
    Yang, Liankuan
    2023 35TH CHINESE CONTROL AND DECISION CONFERENCE, CCDC, 2023, : 2715 - 2720
  • [23] Intrusion Detection System Using Hybrid Convolutional Neural Network
    Samha, Amani K.
    Malik, Nidhi
    Sharma, Deepak
    Kavitha, S.
    Dutta, Papiya
    MOBILE NETWORKS & APPLICATIONS, 2023,
  • [24] A Hybrid Approach for Intrusion Detection System
    Hariyale, Neelam
    Rathore, Manjari Singh
    Prasad, Ritu
    Saurabh, Praneet
    SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 1, 2020, 1048 : 391 - 403
  • [25] Research on Data Pollution Prevention in Network Intrusion Detection Systems Based on Naive Bayes
    Lu, Yinglun
    Xie, Tian
    Shen, Jiyue
    Xu, Sheng
    Sun, Pan
    PROCEEDINGS OF 2024 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, NETWORK SECURITY AND COMMUNICATION TECHNOLOGY, CNSCT 2024, 2024, : 114 - 118
  • [26] Poly Logarithmic Naive Bayes Intrusion Detection System Using Linear Stable PCA Feature Extraction
    Sukhvinder Singh
    Wireless Personal Communications, 2022, 125 : 3117 - 3132
  • [27] Poly Logarithmic Naive Bayes Intrusion Detection System Using Linear Stable PCA Feature Extraction
    Singh, Sukhvinder
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 125 (04) : 3117 - 3132
  • [28] Anomaly-based Intrusion Detection using Tree Augmented Naive Bayes
    Wester, Philip
    Heiding, Fredrik
    Lagerstrom, Robert
    2021 IEEE 25TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS (EDOCW 2021), 2021, : 112 - 121
  • [29] A hybrid method consisting of GA and SVM for intrusion detection system
    Aslahi-Shahri, B. M.
    Rahmani, R.
    Chizari, M.
    Maralani, A.
    Eslami, M.
    Golkar, M. J.
    Ebrahimi, A.
    NEURAL COMPUTING & APPLICATIONS, 2016, 27 (06): : 1669 - 1676
  • [30] A Hybrid Classifier Approach for Network Intrusion Detection
    Arivardhini, S.
    Alamelu, L. Muthu
    Deepika, S.
    2020 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2020, : 824 - 827