Building an efficient intrusion detection system based on feature selection and ensemble classifier

被引:300
|
作者
Zhou, Yuyang [1 ,2 ,3 ]
Cheng, Guang [1 ,2 ,3 ]
Jiang, Shanqing [1 ,4 ]
Dai, Mian [1 ,2 ,3 ]
机构
[1] Southeast Univ, Sch Cyber Sci & Engn, Nanjing, Peoples R China
[2] Minist Educ, Key Lab Comp Network & Informat Integrat, Nanjing, Peoples R China
[3] Southeast Univ, Jiangsu Prov Key Lab Comp Network Technol, Nanjing, Peoples R China
[4] Natl Key Lab Sci & Technol Informat Syst Secur, Beijing, Peoples R China
关键词
Cyber security; Intrusion detection system; Data mining; Feature selection; Ensemble classifier; ALGORITHM; FOREST; MODEL; ATTACKS; IDS;
D O I
10.1016/j.comnet.2020.107247
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection system (IDS) is one of extensively used techniques in a network topology to safeguard the integrity and availability of sensitive assets in the protected systems. Although many supervised and unsupervised learning approaches from the field of machine learning have been used to increase the efficacy of IDSs, it is still a problem for existing intrusion detection algorithms to achieve good performance. First, lots of redundant and irrelevant data in high-dimensional datasets interfere with the classification process of an IDS. Second, an individual classifier may not perform well in the detection of each type of attacks. Third, many models are built for stale datasets, making them less adaptable for novel attacks. Thus, we propose a new intrusion detection framework in this paper, and this framework is based on the feature selection and ensemble learning techniques. In the first step, a heuristic algorithm called CFS-BA is proposed for dimensionality reduction, which selects the optimal subset based on the correlation between features. Then, we introduce an ensemble approach that combines C4.5, Random Forest (RF), and Forest by Penalizing Attributes (Forest PA) algorithms. Finally, voting technique is used to combine the probability distributions of the base learners for attack recognition. The experimental results, using NSL-KDD, AWID, and CIC-IDS2017 datasets, reveal that the proposed CFS-BA-Ensemble method is able to exhibit better performance than other related and state of the art approaches under several metrics.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Efficient Intrusion Detection System in the Cloud Using Fusion Feature Selection Approaches and an Ensemble Classifier
    Bakro, Mhamad
    Kumar, Rakesh Ranjan
    Alabrah, Amerah A.
    Ashraf, Zubair
    Bisoy, Sukant K.
    Parveen, Nikhat
    Khawatmi, Souheil
    Abdelsalam, Ahmed
    ELECTRONICS, 2023, 12 (11)
  • [2] A fast intrusion detection system based on swift wrapper feature selection and speedy ensemble classifier
    Zorarpaci, Ezgi
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 133
  • [3] Feature Selection and Ensemble-Based Intrusion Detection System: An Efficient and Comprehensive Approach
    Jaw, Ebrima
    Wang, Xueming
    SYMMETRY-BASEL, 2021, 13 (10):
  • [4] An Ensemble Intrusion Detection System based on Acute Feature Selection
    Hariprasad, S.
    Deepa, T.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (03) : 8267 - 8280
  • [5] An Ensemble Intrusion Detection System based on Acute Feature Selection
    Hariprasad S
    Deepa T
    Multimedia Tools and Applications, 2024, 83 : 8267 - 8280
  • [6] EFS-LSTM (Ensemble-Based Feature Selection With LSTM) Classifier for Intrusion Detection System
    Preethi, D.
    Khare, Neelu
    INTERNATIONAL JOURNAL OF E-COLLABORATION, 2020, 16 (04) : 72 - 86
  • [7] A Hybrid Intrusion Detection System Based on Feature Selection and Voting Classifier
    Liu, Rong
    Chen, Zemao
    Liu, Jiayi
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 203 - 212
  • [8] An Ensemble Classifier Approach on Different Feature Selection Methods for Intrusion Detection
    Vinutha, H. P.
    Poornima, B.
    INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, INDIA 2017, 2018, 672 : 442 - 451
  • [9] Design of an Intrusion Detection System Based on Distance Feature Using Ensemble Classifier
    Aravind, Mithun M. A.
    Kalaiselvi, V. K. G.
    2017 FOURTH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATION AND NETWORKING (ICSCN), 2017,
  • [10] A Network Intrusion Detection System Based On Ensemble CVM Using Efficient Feature Selection Approach
    Divyasree, T. H.
    Sherly, K. K.
    8TH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING & COMMUNICATIONS (ICACC-2018), 2018, 143 : 442 - 449