A Double-Layered Hybrid Approach for Network Intrusion Detection System Using Combined Naive Bayes and SVM

被引:62
作者
Wisanwanichthan, Treepop [1 ]
Thammawichai, Mason [1 ]
机构
[1] Navaminda Kasatriyadhiraj Royal Air Force Acad, Bangkok 10220, Thailand
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Feature extraction; Support vector machines; Machine learning; Probes; Radio frequency; Principal component analysis; Correlation; Correlation feature selection; double-layered hybrid approach; machine learning; Naive Bayes; intrusion detection system; network security; NSL-KDD; SVM; DEEP LEARNING APPROACH; FEATURE-SELECTION; RANDOM FOREST; SECURITY APPROACH; DETECTION MODEL; MACHINE; CLASSIFIER; ALGORITHM; ENSEMBLE; COLONY;
D O I
10.1109/ACCESS.2021.3118573
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A pattern matching method (signature-based) is widely used in basic network intrusion detection systems (IDS). A more robust method is to use a machine learning classifier to detect anomalies and unseen attacks. However, a single machine learning classifier is unlikely to be able to accurately detect all types of attacks, especially uncommon attacks e.g., Remote2Local (R2L) and User2Root (U2R) due to a large difference in the patterns of attacks. Thus, a hybrid approach offers more promising performance. In this paper, we proposed a Double-Layered Hybrid Approach (DLHA) designed specifically to address the aforementioned problem. We studied common characteristics of different attack categories by creating Principal Component Analysis (PCA) variables that maximize variance from each attack type, and found that R2L and U2R attacks have similar behaviour to normal users. DLHA deploys Naive Bayes classifier as Layer 1 to detect DoS and Probe, and adopts SVM as Layer 2 to distinguish R2L and U2R from normal instances. We compared our work with other published research articles using the NSL-KDD data set. The experimental results suggest that DLHA outperforms several existing state-of-the-art IDS techniques, and is significantly better than any single machine learning classifier by large margins. DLHA also displays an outstanding performance in detecting rare attacks by obtaining a detection rate of 96.67% and 100% from R2L and U2R respectively.
引用
收藏
页码:138432 / 138450
页数:19
相关论文
共 50 条
  • [41] Intrusion Detection Model Using Chi Square Feature Selection and Modified Naive Bayes Classifier
    Thaseen, I. Sumaiya
    Kumar, Ch. Aswani
    PROCEEDINGS OF THE 3RD INTERNATIONAL SYMPOSIUM ON BIG DATA AND CLOUD COMPUTING CHALLENGES (ISBCC - 16'), 2016, 49 : 81 - 91
  • [42] Intrusion Detection System Using Hybrid Convolutional Neural Network
    Samha, Amani K.
    Malik, Nidhi
    Sharma, Deepak
    Kavitha, S.
    Dutta, Papiya
    MOBILE NETWORKS & APPLICATIONS, 2023, 29 (6) : 1719 - 1731
  • [43] A feature selection approach to find optimal feature subsets for the network intrusion detection system
    Seung-Ho Kang
    Kuinam J. Kim
    Cluster Computing, 2016, 19 : 325 - 333
  • [44] A Hybrid Approach for Intrusion Detection System
    Hariyale, Neelam
    Rathore, Manjari Singh
    Prasad, Ritu
    Saurabh, Praneet
    SOFT COMPUTING FOR PROBLEM SOLVING, SOCPROS 2018, VOL 1, 2020, 1048 : 391 - 403
  • [45] A feed forward deep neural network model using feature selection for cloud intrusion detection system
    Sharma, Hidangmayum Satyajeet
    Singh, Khundrakpam Johnson
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (09)
  • [46] A feature selection approach to find optimal feature subsets for the network intrusion detection system
    Kang, Seung-Ho
    Kim, Kuinam J.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2016, 19 (01): : 325 - 333
  • [47] Poly Logarithmic Naive Bayes Intrusion Detection System Using Linear Stable PCA Feature Extraction
    Singh, Sukhvinder
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 125 (04) : 3117 - 3132
  • [48] Hybrid Classification for High-Speed and High-Accuracy Network Intrusion Detection System
    Kim, Taehoon
    Pak, Wooguil
    IEEE ACCESS, 2021, 9 : 83806 - 83817
  • [49] A Hybrid Feature Reduced Approach for Intrusion Detection System
    Garg, Lavisha
    Akashdeep
    Aggarwal, Naveen
    COMPUTING AND NETWORK SUSTAINABILITY, 2019, 75
  • [50] Network Intrusion Detection using Hybrid Machine Learning
    Chuang, Po-Jen
    Li, Si-Han
    2019 INTERNATIONAL CONFERENCE ON FUZZY THEORY AND ITS APPLICATIONS (IFUZZY), 2019, : 289 - 293