Effective network intrusion detection using stacking-based ensemble approach

被引:4
|
作者
Ali, Muhammad [1 ,2 ]
Haque, Mansoor-ul [1 ,2 ]
Durad, Muhammad Hanif [1 ,2 ]
Usman, Anila [1 ]
Mohsin, Syed Muhammad [3 ,4 ]
Mujlid, Hana [5 ]
Maple, Carsten [6 ]
机构
[1] Pakistan Inst Engn & Appl Sci, Dept Comp & Informat Sci, Islamabad 45650, Pakistan
[2] Pakistan Inst Engn & Appl Sci, Crit Infrastruct Protect & Malware Anal Lab, Islamabad 45650, Pakistan
[3] COMSATS Univ Islamabad, Dept Comp Sci, Islamabad 45550, Pakistan
[4] Virtual Univ Pakistan, Coll Intellectual Novitiates COIN, Lahore 55150, Pakistan
[5] Taif Univ, Dept Comp Engn, Taif, Saudi Arabia
[6] Univ Warwick, Cyber Secur Ctr, Coventry, England
关键词
Machine learning; Intrusion detection system; Denial of service; Ensemble-based learning; CICIDS2017; GNS-3; Performance metrics; DETECTION SYSTEMS; ARTIFICIAL-INTELLIGENCE;
D O I
10.1007/s10207-023-00718-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing demand for communication between networked devices connected either through an intranet or the internet increases the need for a reliable and accurate network defense mechanism. Network intrusion detection systems (NIDSs), which are used to detect malicious or anomalous network traffic, are an integral part of network defense. This research aims to address some of the issues faced by anomaly-based network intrusion detection systems. In this research, we first identify some limitations of the legacy NIDS datasets, including a recent CICIDS2017 dataset, which lead us to develop our novel dataset, CIPMAIDS2023-1. Then, we propose a stacking-based ensemble approach that outperforms the overall state of the art for NIDS. Various attack scenarios were implemented along with benign user traffic on the network topology created using graphical network simulator-3 (GNS-3). Key flow features are extracted using cicflowmeter for each attack and are evaluated to analyze their behavior. Several different machine learning approaches are applied to the features extracted from the traffic data, and their performance is compared. The results show that the stacking-based ensemble approach is the most promising and achieves the highest weighted F1-score of 98.24%.
引用
收藏
页码:1781 / 1798
页数:18
相关论文
共 50 条
  • [1] Effective network intrusion detection using stacking-based ensemble approach
    Muhammad Ali
    Mansoor-ul- Haque
    Muhammad Hanif Durad
    Anila Usman
    Syed Muhammad Mohsin
    Hana Mujlid
    Carsten Maple
    [J]. International Journal of Information Security, 2023, 22 : 1781 - 1798
  • [2] A Stacking-Based Deep Neural Network Approach for Effective Network Anomaly Detection
    Nkenyereye, Lewis
    Tama, Bayu Adhi
    Lim, Sunghoon
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 66 (02): : 2217 - 2227
  • [3] Optimum-path forest stacking-based ensemble for intrusion detection
    Bertoni, Mateus A.
    de Rosa, Gustavo H.
    Brega, Jose R. F.
    [J]. EVOLUTIONARY INTELLIGENCE, 2022, 15 (03) : 2037 - 2054
  • [4] Optimum-path forest stacking-based ensemble for intrusion detection
    Mateus A. Bertoni
    Gustavo H. de Rosa
    Jose R. F. Brega
    [J]. Evolutionary Intelligence, 2022, 15 : 2037 - 2054
  • [5] A Stacking Ensemble for Network Intrusion Detection Using Heterogeneous Datasets
    Rajagopal, Smitha
    Kundapur, Poornima Panduranga
    Hareesha, Katiganere Siddaramappa
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [6] lAnalyzing Intrusion Detection System: An Ensemble based Stacking Approach
    Roy, Sanjiban Sekhar
    Krishna, P. Venkata
    Yenduri, Sumanth
    [J]. 2014 IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY (ISSPIT), 2014, : 307 - 309
  • [7] A Stacking-based Ensemble Framework for Automatic Depression Detection using Audio Signals
    Mamidisetti, Suresh
    Reddy, A. Mallikarjuna
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (07) : 603 - 612
  • [8] Stacking-based ensemble model for malware detection in android devices
    Joshi A.
    Kumar S.
    [J]. International Journal of Information Technology, 2023, 15 (6) : 2907 - 2915
  • [9] Modified stacking ensemble approach to detect network intrusion
    Demir, Necati
    Dalkilic, Gokhan
    [J]. TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2018, 26 (01) : 418 - 433
  • [10] Machine learning based framework for network intrusion detection system using stacking ensemble technique
    Parashar, Anshu
    Saggu, Kuljot Singh
    Garg, Anupam
    [J]. INDIAN JOURNAL OF ENGINEERING AND MATERIALS SCIENCES, 2022, 29 (04) : 509 - 518