A two-stage intrusion detection method based on light gradient boosting machine and autoencoder

被引:2
|
作者
Zhang, Hao [1 ,2 ]
Ge, Lina [1 ,2 ,3 ]
Zhang, Guifen [1 ,2 ]
Fan, Jingwei [2 ,4 ]
Li, Denghui [1 ,2 ]
Xu, Chenyang [1 ,2 ]
机构
[1] Guangxi Minzu Univ, Sch Artificial Intelligence, Nanning 530006, Peoples R China
[2] Guangxi Minzu Univ, Key Lab Network Commun Engn, Nanning 530006, Peoples R China
[3] Guangxi Key Lab Hybrid Computat & IC Design Anal, Nanning 530006, Peoples R China
[4] Guangxi Minzu Univ, Coll Elect Informat, Nanning 530006, Peoples R China
基金
中国国家自然科学基金;
关键词
cybersecurity; feature selection; focal loss; intrusion detection systems; machine learning; DEEP LEARNING APPROACH; ENSEMBLE; EFFICIENT; SVM;
D O I
10.3934/mbe.2023301
中图分类号
Q [生物科学];
学科分类号
07 ; 0710 ; 09 ;
摘要
Intrusion detection systems can detect potential attacks and raise alerts on time. However, dimensionality curses and zero-day attacks pose challenges to intrusion detection systems. From a data perspective, the dimensionality curse leads to the low efficiency of intrusion detection systems. From the attack perspective, the increasing number of zero-day attacks overwhelms the intrusion detection system. To address these problems, this paper proposes a novel detection framework based on light gradient boosting machine (LightGBM) and autoencoder. The recursive feature elimination (RFE) method is first used for dimensionality reduction in this framework. Then a focal loss (FL) function is introduced into the LightGBM classifier to boost the learning of difficult samples. Finally, a two-stage prediction step with LightGBM and autoencoder is performed. In the first stage, pre-decision is conducted with LightGBM. In the second stage, a residual is used to make a secondary decision for samples with a normal class. The experiments were performed on the NSL-KDD and UNSWNB15 datasets, and compared with the classical method. It was found that the proposed method is superior to other methods and reduces the time overhead. In addition, the existing advanced methods were also compared in this study, and the results show that the proposed method is above 90% for accuracy, recall, and F1 score on both datasets. It is further concluded that our method is valid when compared with other advanced techniques.
引用
收藏
页码:6966 / 6992
页数:27
相关论文
共 50 条
  • [21] A Network Intrusion Detection Method Based on Stacked Autoencoder and LSTM
    Yan, Yu
    Qi, Lin
    Wang, Jie
    Lin, Yun
    Chen, Lei
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [22] A Convolutional Autoencoder Based Method with SMOTE for Cyber Intrusion Detection
    She, Xinyi
    Sekiya, Yuji
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 2565 - 2573
  • [23] A two-stage technique to improve intrusion detection systems based on data mining algorithms
    Fatma, Hachmi
    Mohamed, Limam
    2013 5TH INTERNATIONAL CONFERENCE ON MODELING, SIMULATION AND APPLIED OPTIMIZATION (ICMSAO), 2013,
  • [24] Gradient Boosting Feature Selection With Machine Learning Classifiers for Intrusion Detection on Power Grids
    Upadhyay, Darshana
    Manero, Jaume
    Zaman, Marzia
    Sampalli, Srinivas
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 1104 - 1116
  • [25] AI-Based Two-Stage Intrusion Detection for Software Defined IoT Networks
    Li, Jiaqi
    Zhao, Zhifeng
    Li, Rongpeng
    Zhang, Honggang
    IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02) : 2093 - 2102
  • [26] Automatic detection method of cracks from concrete surface imagery using two-step light gradient boosting machine
    Chun, Pang-jo
    Izumi, Shota
    Yamane, Tatsuro
    COMPUTER-AIDED CIVIL AND INFRASTRUCTURE ENGINEERING, 2021, 36 (01) : 61 - 72
  • [27] A Reconfigurable Architecture for Rotation Invariant Multi-View Face Detection Based on a Novel Two-Stage Boosting Method
    Jinbo Xu
    Yong Dou
    Zhengbin Pang
    EURASIP Journal on Advances in Signal Processing, 2009
  • [28] A Reconfigurable Architecture for Rotation Invariant Multi-View Face Detection Based on a Novel Two-Stage Boosting Method
    Xu, Jinbo
    Dou, Yong
    Pang, Zhengbin
    EURASIP JOURNAL ON ADVANCES IN SIGNAL PROCESSING, 2009,
  • [29] A Hybrid Detection System for DDoS Attacks Based on Deep Sparse Autoencoder and Light Gradient Boost Machine
    Batchu, Raj Kumar
    Seetha, Hari
    JOURNAL OF INFORMATION & KNOWLEDGE MANAGEMENT, 2023, 22 (01)
  • [30] Pedestrian Detection Method Based on Two-Stage Fusion of Visible Light Image and Thermal Infrared Image
    Zhang, Yugui
    Zhai, Bo
    Wang, Gang
    Lin, Jianchu
    ELECTRONICS, 2023, 12 (14)