An efficient intrusion detection method based on Rime-NeoEvo Optimizer algorithm
摘要
As network environments grow more complex and dynamic, intrusion detection systems (IDS) suffer reduced efficiency and accuracy due to redundant features, creating an urgent need for more effective feature selection (FS) methods. Current feature selection methods frequently suffer from premature convergence to local optima, thereby failing to identify truly optimal feature subsets and consequently hindering intrusion detection performance while exacerbating network security risks. To address these issues, this study introduces the Rime-NeoEvo algorithm, which leverages the NeoEvo strategy to balance exploration and exploitation, achieving fast optimization. The binary variant is applied to IDS, combining superior optimization capability with fitness function evaluation to accurately identify optimal feature subsets. Extensive evaluation of the Rime-NeoEvo algorithm was conducted using benchmark functions and three classic datasets (NSL-KDD, UNSW-NB15, and CIC-IDS2018). The results demonstrate that the algorithm achieves faster convergence and higher precision. When implemented in IDS, it markedly improves key performance metrics, including accuracy, true positive rate (TPR), and F1-score, while effectively reducing the false positive rate (FPR), enhancing overall detection performance and efficacy.