A Double-Layered Hybrid Approach for Network Intrusion Detection System Using Combined Naive Bayes and SVM

被引:56
作者
Wisanwanichthan, Treepop [1 ]
Thammawichai, Mason [1 ]
机构
[1] Navaminda Kasatriyadhiraj Royal Air Force Acad, Bangkok 10220, Thailand
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Feature extraction; Support vector machines; Machine learning; Probes; Radio frequency; Principal component analysis; Correlation; Correlation feature selection; double-layered hybrid approach; machine learning; Naive Bayes; intrusion detection system; network security; NSL-KDD; SVM; DEEP LEARNING APPROACH; FEATURE-SELECTION; RANDOM FOREST; SECURITY APPROACH; DETECTION MODEL; MACHINE; CLASSIFIER; ALGORITHM; ENSEMBLE; COLONY;
D O I
10.1109/ACCESS.2021.3118573
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A pattern matching method (signature-based) is widely used in basic network intrusion detection systems (IDS). A more robust method is to use a machine learning classifier to detect anomalies and unseen attacks. However, a single machine learning classifier is unlikely to be able to accurately detect all types of attacks, especially uncommon attacks e.g., Remote2Local (R2L) and User2Root (U2R) due to a large difference in the patterns of attacks. Thus, a hybrid approach offers more promising performance. In this paper, we proposed a Double-Layered Hybrid Approach (DLHA) designed specifically to address the aforementioned problem. We studied common characteristics of different attack categories by creating Principal Component Analysis (PCA) variables that maximize variance from each attack type, and found that R2L and U2R attacks have similar behaviour to normal users. DLHA deploys Naive Bayes classifier as Layer 1 to detect DoS and Probe, and adopts SVM as Layer 2 to distinguish R2L and U2R from normal instances. We compared our work with other published research articles using the NSL-KDD data set. The experimental results suggest that DLHA outperforms several existing state-of-the-art IDS techniques, and is significantly better than any single machine learning classifier by large margins. DLHA also displays an outstanding performance in detecting rare attacks by obtaining a detection rate of 96.67% and 100% from R2L and U2R respectively.
引用
收藏
页码:138432 / 138450
页数:19
相关论文
共 50 条
  • [31] A Hybrid Metaheuristic Algorithm for Features Dimensionality Reduction in Network Intrusion Detection System
    Balogun, Bukola Fatimah
    Gbolagade, Kazeem Alagbe
    Arowolo, Micheal Olaolu
    Saheed, Yakub Kayode
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT IX, 2021, 12957 : 101 - 114
  • [32] Anomaly based Intrusion Detection using Hybrid Learning Approach of combining k-Medoids Clustering and Naive Bayes Classification
    Chitrakar, Roshan
    Huang Chuanhe
    2012 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING (WICOM), 2012,
  • [33] DeepShield: A Hybrid Deep Learning Approach for Effective Network Intrusion Detection
    Lin, Hongjie
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (07) : 1094 - 1104
  • [34] An SDN-based Intrusion Detection System using SVM with Selective Logging for IP Traceback
    Hadem, Pynbianglut
    Saikia, Dilip Kumar
    Moulik, Soumen
    COMPUTER NETWORKS, 2021, 191
  • [35] Weighted Naive Bayes Approach for Imbalanced Indoor Positioning System Using UWB
    Che, Fuhu
    Bin Abbas, Waqas
    Ahmed, Qasim Zeeshan
    Amjad, Bisma
    Khan, Faheem Ahmad
    Lazaridis, Pavlos I.
    2022 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (BLACKSEACOM), 2022, : 72 - 76
  • [36] An Innovative Perceptual Pigeon Galvanized Optimization (PPGO) Based Likelihood Naive Bayes (LNB) Classification Approach for Network Intrusion Detection System
    Shitharth, S.
    Kshirsagar, Pravin R.
    Balachandran, Praveen Kumar
    Alyoubi, Khaled H.
    Khadidos, Alaa O.
    IEEE ACCESS, 2022, 10 : 46424 - 46441
  • [37] Double-Layered Hybrid Neural Network Approach for Solving Mixed Integer Quadratic Bilevel Problems
    Yaakob, Shamshul Bahar
    Watada, Junzo
    INTEGRATED UNCERTAINTY MANAGEMENT AND APPLICATIONS, 2010, 68 : 221 - 230
  • [38] Email Spam Detection using integrated approach of Naive Bayes and Particle Swarm Optimization
    Agarwal, Kriti
    Kumar, Tarun
    PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICICCS), 2018, : 685 - 690
  • [39] Unsupervised learning approach for network intrusion detection system using autoencoders
    Choi, Hyunseung
    Kim, Mintae
    Lee, Gyubok
    Kim, Wooju
    JOURNAL OF SUPERCOMPUTING, 2019, 75 (09) : 5597 - 5621
  • [40] Unsupervised learning approach for network intrusion detection system using autoencoders
    Hyunseung Choi
    Mintae Kim
    Gyubok Lee
    Wooju Kim
    The Journal of Supercomputing, 2019, 75 : 5597 - 5621