Comparative research on network intrusion detection methods based on machine learning

被引:46
|
作者
Zhang, Chunying [1 ]
Jia, Donghao [1 ]
Wang, Liya [1 ]
Wang, Wenjie [1 ]
Liu, Fengchun [2 ]
Yang, Aimin [1 ]
机构
[1] North China Univ Sci & Technol, Coll Sci, Qinhuangdao, Hebei, Peoples R China
[2] North China Univ Sci & Technol, Qianan Coll, Qinhuangdao, Hebei, Peoples R China
关键词
Network intrusion detection; Machine learning; Deep learning; Comparative experiment; ATTACK DETECTION;
D O I
10.1016/j.cose.2022.102861
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection system is an essential part of network security research. It detects intrusion behaviors through active defense technology and takes emergency measures such as alerting and terminating intrusions. With the rapid development of machine learning technology, more and more researchers apply machine learning algorithms to network intrusion detection to improve detection efficiency and accuracy. Due to the different principles of various algorithms, they also have their advantages and disadvantages. To construct the dominant algorithm model in the field of network intrusion detection and provide the accuracy value, this paper systematically combs the application literature of machine learning algorithms in intrusion detection in the past ten years. A review is made from three categories: traditional machine learning, ensemble learning, and deep learning. Then, this paper selects the KDD CUP99 and NSL-KDD datasets to conduct comparative experiments on decision trees, Naive Bayes, support vector machines, random forests, XGBoost, convolutional neural networks, and recurrent neural networks. The detection accuracy, F1, AUC, and other indicators of these algorithms on different data sets are compared. The experimental results show that the effect of the ensemble learning algorithm is generally better. The Naive Bayes algorithm has low accuracy in recognizing the learned data, but it has obvious advantages when facing new types of attacks, and the training speed is faster. The deep learning algorithm is not particularly prominent in this experiment, but its optimal results are affected by the structure, hyperparameters, and the number of training iterations, which need further in-depth study. Finally, the main challenges facing the current network intrusion detection field are summarized, and the future research directions have been prospected. (C) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Research on Network Intrusion Detection Technology Based on Machine Learning
    Wu, Fei
    Li, Ting
    Wu, Zhen
    Wu, ShuLin
    Xiao, ChuanQi
    INTERNATIONAL JOURNAL OF WIRELESS INFORMATION NETWORKS, 2021, 28 (03) : 262 - 275
  • [2] Research on Network Intrusion Detection Technology Based on Machine Learning
    Fei Wu
    Ting Li
    Zhen Wu
    ShuLin Wu
    ChuanQi Xiao
    International Journal of Wireless Information Networks, 2021, 28 : 262 - 275
  • [3] Research on Network Intrusion Detection Based on SMOTE Algorithm and Machine Learning
    Zhang Y.
    Zhang T.
    Chen J.
    Wang Y.
    Zou Q.
    Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2019, 39 (12): : 1258 - 1262
  • [4] Research On Network Security Intrusion Detection System Based On Machine Learning
    Luo, Yin
    International Journal of Network Security, 2021, 23 (03) : 490 - 495
  • [5] Research on Network Intrusion Detection Based on Improved Machine Learning Method
    Jian, Yan
    Jian, Liang
    Dong, Xiaoyang
    International Journal of Network Security, 2022, 24 (03): : 533 - 540
  • [6] Machine Learning Based Network Intrusion Detection
    Lee, Chie-Hong
    Su, Yann-Yean
    Lin, Yu-Chun
    Lee, Shie-Jue
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND APPLICATIONS (ICCIA), 2017, : 79 - 83
  • [7] Optimisation of Machine Learning Based Data Mining Methods for Network Intrusion Detection
    Li, Mingxiao
    Li, Ziqing
    Liu, Chenlong
    Chen, Wanqi
    Ma, Chaojie
    2024 6TH INTERNATIONAL CONFERENCE ON BIG-DATA SERVICE AND INTELLIGENT COMPUTATION, BDSIC 2024, 2024, : 17 - 25
  • [8] Adversarial machine learning for network intrusion detection: A comparative study
    Jmila, Houda
    Ibn Khedher, Mohamed
    COMPUTER NETWORKS, 2022, 214
  • [9] Machine Learning for Network Intrusion Detection-A Comparative Study
    Al Lail, Mustafa
    Garcia, Alejandro
    Olivo, Saul
    FUTURE INTERNET, 2023, 15 (07):
  • [10] Network intrusion detection methods based on deep learning
    Li X.
    Zhang S.
    Recent Patents on Engineering, 2021, 15 (04):