Multi-layer stacking ensemble learners for low footprint network intrusion detection

被引:16
|
作者
Shafieian, Saeed [1 ]
Zulkernine, Mohammad [1 ]
机构
[1] Queens Univ, Sch Comp, Kingston, ON, Canada
关键词
Network intrusion detection; Anomaly detection; Ensemble learning; Stacking ensemble learning; Low footprint intrusion;
D O I
10.1007/s40747-022-00809-3
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Machine learning has become the standard solution to problems in many areas, such as image recognition, natural language processing, and spam detection. In the area of network intrusion detection, machine learning techniques have also been successfully used to detect anomalies in network traffic. However, there is less tolerance in the network intrusion detection domain in terms of errors, especially false positives. In this paper, we define strict acceptance criteria, and show that only very few ensemble learning classifiers are able to meet them in detecting low footprint network intrusions. We compare bagging, boosting, and stacking techniques, and show how methods such as multi-layer stacking can outperform other ensemble techniques and non-ensemble models in detecting such intrusions. We show how different variations on a stacking ensemble model can play a significant role on the classification performance. Malicious examples in our dataset are from the network intrusions that exfiltrate data from a target machine. The benign examples are captured by network taps in geographically different locations on a big corporate network. Among hundreds of ensemble models based on seven different base learners, only three multi-layer stacking models meet the strict acceptance criteria, and achieve an F1 score of 0.99, and a false-positive rate of 0.001. Furthermore, we show that our ensemble models outperform different deep neural network models in classifying low footprint network intrusions.
引用
收藏
页码:3787 / 3799
页数:13
相关论文
共 50 条
  • [1] Multi-layer stacking ensemble learners for low footprint network intrusion detection
    Saeed Shafieian
    Mohammad Zulkernine
    [J]. Complex & Intelligent Systems, 2023, 9 : 3787 - 3799
  • [2] Multi-dimensional feature fusion and stacking ensemble mechanism for network intrusion detection
    Zhang, Hao
    Li, Jie-Ling
    Liu, Xi-Meng
    Dong, Chen
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 122 : 130 - 143
  • [3] Multi-Layer Mapping of Cyberspace for Intrusion Detection
    Shao, Sicong
    Satam, Pratik
    Satam, Shalaka
    Al-Awady, Khalid
    Ditzler, Gregory
    Hariri, Salim
    Tunc, Cihan
    [J]. 2021 IEEE/ACS 18TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2021,
  • [4] A Stacking Ensemble for Network Intrusion Detection Using Heterogeneous Datasets
    Rajagopal, Smitha
    Kundapur, Poornima Panduranga
    Hareesha, Katiganere Siddaramappa
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [5] Research on Multi-layer Adaptive Intrusion Detection Based on Clustering and Neural Network
    Chen, Yingyue
    [J]. 14TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND EDUCATION (ICCSE 2019), 2019, : 1 - 4
  • [6] Optimized Multi-Layer Hierarchical Network Intrusion Detection System with Genetic Algorithms
    Santikellur, Pranesh
    Haque, Tahreem
    Al-Zewairi, Malek
    Chakraborty, Rajat Subhra
    [J]. 2019 2ND INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2019, : 1 - 7
  • [7] Application of an Improved multi-layer BP Neural Network Algorithm in Intrusion Detection
    Zhang, Hao
    Li, Bin
    [J]. PROCEEDINGS OF 2016 SIXTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2016), 2016, : 619 - 622
  • [8] Distributed Intrusion Detection System in a Multi-Layer Network Architecture of Smart Grids
    Zhang, Yichi
    Wang, Lingfeng
    Sun, Weiqing
    Green, Robert C., II
    Alam, Mansoor
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (04) : 796 - 808
  • [9] A Multi-layer Stack Ensemble Approach to Improve Intrusion Detection System's Prediction Accuracy
    Aryeh, Felix Larbi
    Alese, Boniface Kayode
    [J]. INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST-2020), 2020, : 30 - 35
  • [10] Multi-Layer Bayesian Based Intrusion Detection System
    Altwaijry, Hesham
    Algarny, Saeed
    [J]. WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, WCECS 2011, VOL II, 2011, : 918 - 922