An improved framework for network intrusion detection using machine learning
摘要
In light of individuals and companies’ increasing dependence, internet users’ anxieties about the confidentiality and safety of their online transactions, as well as cyber-security has garnered considerable attention. Systems for Network Intrusion Detection (NIDS) that utilize machine learning (ML) have recently been created in order to guard against malicious online behaviors. The ML-based NIDS framework proposed in this study is a unique multi-stage optimization method that keeps detection performance while reducing computing complexity. The minimum appropriate training sample size is determined by analyzing the impact of oversampling methods on the model training sample size. Moreover, it contrasts the effects of information gain and recursive feature elimination-based feature selection techniques on the rate and complexity of detection. Based on the kind of attack, such as Exploits, Fuzzers, Analyses, Backdoors, Denial of Service (DoS), Reconnaissance, Shellcode and Worms, port scanning, brute force, web assaults, botnets, and penetration, the identified malicious traffic is categorized. To enhance the NIDS’s functionality, other ML hyperparameter optimization approaches are also being researched. The CICIDS 2017 and UNSW-NB 2015 datasets, two significant detection methods for intrusion datasets are used to evaluate the effectiveness of the suggested technique. The suggested model greatly decreases the needed feature set size (up to 78%) and training sample size (up to 61%), according to experimental data. Moreover, hyper-parameter tuning improves the model’s performance, with detection accuracies for both datasets above 99%. It is determined how effective the ML classification model is using accuracy, precision, recall, and F1-Score. The detection module’s accuracy in predicting the kind of attack that has occurred determines the final results.