Building an efficient intrusion detection system based on feature selection and ensemble classifier

被引:300
|
作者
Zhou, Yuyang [1 ,2 ,3 ]
Cheng, Guang [1 ,2 ,3 ]
Jiang, Shanqing [1 ,4 ]
Dai, Mian [1 ,2 ,3 ]
机构
[1] Southeast Univ, Sch Cyber Sci & Engn, Nanjing, Peoples R China
[2] Minist Educ, Key Lab Comp Network & Informat Integrat, Nanjing, Peoples R China
[3] Southeast Univ, Jiangsu Prov Key Lab Comp Network Technol, Nanjing, Peoples R China
[4] Natl Key Lab Sci & Technol Informat Syst Secur, Beijing, Peoples R China
关键词
Cyber security; Intrusion detection system; Data mining; Feature selection; Ensemble classifier; ALGORITHM; FOREST; MODEL; ATTACKS; IDS;
D O I
10.1016/j.comnet.2020.107247
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection system (IDS) is one of extensively used techniques in a network topology to safeguard the integrity and availability of sensitive assets in the protected systems. Although many supervised and unsupervised learning approaches from the field of machine learning have been used to increase the efficacy of IDSs, it is still a problem for existing intrusion detection algorithms to achieve good performance. First, lots of redundant and irrelevant data in high-dimensional datasets interfere with the classification process of an IDS. Second, an individual classifier may not perform well in the detection of each type of attacks. Third, many models are built for stale datasets, making them less adaptable for novel attacks. Thus, we propose a new intrusion detection framework in this paper, and this framework is based on the feature selection and ensemble learning techniques. In the first step, a heuristic algorithm called CFS-BA is proposed for dimensionality reduction, which selects the optimal subset based on the correlation between features. Then, we introduce an ensemble approach that combines C4.5, Random Forest (RF), and Forest by Penalizing Attributes (Forest PA) algorithms. Finally, voting technique is used to combine the probability distributions of the base learners for attack recognition. The experimental results, using NSL-KDD, AWID, and CIC-IDS2017 datasets, reveal that the proposed CFS-BA-Ensemble method is able to exhibit better performance than other related and state of the art approaches under several metrics.
引用
收藏
页数:17
相关论文
共 50 条
  • [11] Attribute Selection and Ensemble Classifier based Novel Approach to Intrusion Detection System
    Kunal
    Dua, Mohit
    INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND DATA SCIENCE, 2020, 167 : 2191 - 2199
  • [12] An enhanced whale optimizer based feature selection technique with effective ensemble classifier for network intrusion detection system
    Nandhini, U.
    Kumar, S. V. N. Santhosh
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2025, 18 (02)
  • [13] Hybrid ensemble techniques used for classifier and feature selection in intrusion detection systems
    Kharwar, Ankit
    Thakor, Devendra
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2022, 28 (04) : 389 - 413
  • [14] Efficient feature selection algorithm toward building lightweight intrusion detection system
    Chen, You
    Shen, Hua-Wei
    Li, Yang
    Cheng, Xue-Qi
    Jisuanji Xuebao/Chinese Journal of Computers, 2007, 30 (08): : 1398 - 1408
  • [15] A Hybrid Intrusion Detection System Based on Feature Selection and Weighted Stacking Classifier
    Zhao, Ruizhe
    Mu, Yingxue
    Zou, Long
    Wen, Xiumei
    IEEE ACCESS, 2022, 10 : 71414 - 71426
  • [16] An Efficient Intrusion Detection Framework Based on Embedding Feature Selection and Ensemble Learning Technique
    Mokbal, Fawaz
    Dan, Wang
    Osman, Musa
    Ping, Yang
    Alsamhi, Saeed
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2022, 19 (02) : 237 - 248
  • [17] A Review on Feature Selection and Ensemble Techniques for Intrusion Detection System
    Torabi, Majid
    Udzir, Nur Izura
    Abdullah, Mohd Taufik
    Yaakob, Razali
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (05) : 538 - 553
  • [18] Heterogeneous Ensemble Feature Selection for Network Intrusion Detection System
    Yeshalem Gezahegn Damtew
    Hongmei Chen
    Zhong Yuan
    International Journal of Computational Intelligence Systems, 16
  • [19] Heterogeneous Ensemble Feature Selection for Network Intrusion Detection System
    Damtew, Yeshalem Gezahegn
    Chen, Hongmei
    Yuan, Zhong
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)
  • [20] Flow based anomaly intrusion detection system using ensemble classifier with Feature Impact Scale
    V. Jyothsna
    K. Munivara Prasad
    K. Rajiv
    G. Ramesh Chandra
    Cluster Computing, 2021, 24 : 2461 - 2478