An Enhanced Anomaly Detection in Web Traffic Using a Stack of Classifier Ensemble

被引:59
|
作者
Tama, Bayu Adhi [1 ]
Nkenyereye, Lewis [2 ]
Islam, S. M. Riazul [3 ]
Kwak, Kyung-Sup [4 ]
机构
[1] Pohang Univ Sci & Technol POSTECH, Dept Mech Engn, Gyeongbuk 37673, South Korea
[2] Sejong Univ, Dept Comp & Informat Secur, Seoul 05006, South Korea
[3] Sejong Univ, Dept Comp Sci & Engn, Seoul 05006, South Korea
[4] Inha Univ, Dept Informat & Commun Engn, Incheon 22212, South Korea
基金
新加坡国家研究基金会;
关键词
Random forest; gradient boosting machine; Web attack; performance benchmark; anomaly-based IDSs; significance tests; INTRUSION-DETECTION; MODEL; IDS;
D O I
10.1109/ACCESS.2020.2969428
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Web attack protection system is extremely essential in today & x2019;s information age. Classifier ensembles have been considered for anomaly-based intrusion detection in Web traffic. However, they suffer from an unsatisfactory performance due to a poor ensemble design. This paper proposes a stacked ensemble for anomaly-based intrusion detection systems in a Web application. Unlike a conventional stacking, where some single weak learners are prevalently used, the proposed stacked ensemble is an ensemble architecture, yet its base learners are other ensembles learners, i.e. random forest, gradient boosting machine, and XGBoost. To prove the generalizability of the proposed model, two datasets that are specifically used for attack detection in a Web application, i.e. CSIC-2010v2 and CICIDS-2017 are used in the experiment. Furthermore, the proposed model significantly surpasses existing Web attack detection techniques concerning the accuracy and false positive rate metrics. Validation result on the CICIDS-2017, NSL-KDD, and UNSW-NB15 dataset also ameliorate the ones obtained by some recent techniques. Finally, the performance of all classification algorithms in terms of a two-step statistical significance test is further discussed, providing a value-added contribution to the current literature.
引用
收藏
页码:24120 / 24134
页数:15
相关论文
共 50 条
  • [21] An Enhanced Contrastive Ensemble Learning Method for Anomaly Sound Detection
    Liao, Jingneng
    Yang, Fei
    Lu, Xiaoqing
    APPLIED SCIENCES-BASEL, 2025, 15 (03):
  • [22] Revisiting Deep Ensemble Uncertainty for Enhanced Medical Anomaly Detection
    Gu, Yi
    Lin, Yi
    Cheng, Kwang-Ting
    Chen, Hao
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION - MICCAI 2024, PT VI, 2024, 15006 : 520 - 530
  • [23] Mathematical Validation of Proposed Machine Learning Classifier for Heterogeneous Traffic and Anomaly Detection
    Guezzaz, Azidine
    Asimi, Younes
    Azrour, Mourade
    Asimi, Ahmed
    BIG DATA MINING AND ANALYTICS, 2021, 4 (01): : 18 - 24
  • [24] Mathematical Validation of Proposed Machine Learning Classifier for Heterogeneous Traffic and Anomaly Detection
    Azidine Guezzaz
    Younes Asimi
    Mourade Azrour
    Ahmed Asimi
    Big Data Mining and Analytics, 2021, 4 (01) : 18 - 24
  • [25] Microaneurysm Detection in Retinal Images Using an Ensemble Classifier
    Habib, M. M.
    Welikala, R. A.
    Hoppe, A.
    Owen, C. G.
    Rudnicka, A. R.
    Barman, S. A.
    2016 SIXTH INTERNATIONAL CONFERENCE ON IMAGE PROCESSING THEORY, TOOLS AND APPLICATIONS (IPTA), 2016,
  • [26] Cardiovascular disease detection using a new ensemble classifier
    Esfahani, Hamidreza Ashrafi
    Ghazanfari, Morteza
    2017 IEEE 4TH INTERNATIONAL CONFERENCE ON KNOWLEDGE-BASED ENGINEERING AND INNOVATION (KBEI), 2017, : 1011 - 1014
  • [27] Web Spam Detection using SVM Classifier
    Patil, Rahul C.
    Patil, D. R.
    PROCEEDINGS OF 2015 IEEE 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO), 2015,
  • [28] Enhanced Intrusion Detection with Advanced Deep Features and Ensemble Classifier Techniques
    Pawan Toralkar
    Kavita Mainalli
    Shridhar Allagi
    Sanjoy Kumar Debnath
    Susama Bagchi
    Wai Yie Leong
    Muhammad Numan Ali Khan
    SN Computer Science, 6 (4)
  • [29] USING R FOR ANOMALY DETECTION IN NETWORK TRAFFIC
    Hock, Denis
    Kappes, Martin
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INTERNET TECHNOLOGIES AND APPLICATIONS (ITA 13), 2013, : 98 - 105
  • [30] Identification of Source Applications for Enhanced Traffic Analysis and Anomaly Detection
    Zuquete, Andre
    Rocha, Miguel
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012, : 6694 - 6698