<p>Accurate prediction of intrusion attacks is crucial in the era of Internet of Things to detect and respond promptly to suspicious activities to minimise the damage caused by those attacks. The instances of attacks are always much less than normal traffic and machine learning models are used to detect those comparatively smaller attack classes. For machine learning models the imbalance of classes in the training data results in better accuracy of prediction for majority classes and much less accurate detection of minority classes. In this paper, we propose a class-based classification framework to address the imbalance problem in different categories for network intrusion detection. In the first layer, we train a model for the multi-attack detection and find the class with the best accuracy. Next, the samples labelled as this class are removed while the rest of the data are used to train the model in the next layer. Similar to the previous layer, we train this model for the multi-attack detection and find the class with the best accuracy. This process is repeated until there are only three classes left for training. This model only focuses on the class that has the best performance in each layer. In the prediction phase, we apply the exact matching strategy layer by layer. Once the class is matched, we return the label as the final result; otherwise go to the next layer until a label is matched. The experimental results show that our proposed class-based strategy can improve the performance of the prediction models used. Among all the results, our class-based CatBoost has the best performance in terms of precision, recall, and F1-score where its accuracy is 0.76, the macro average of [precision, recall, F1-score] is [0.75, 0.71, 0.72], and the weighted average of [precision, recall, F1-score] is [0.75, 0.76, 0.75]. These results demonstrated that our class-based technique is effective for multi-attack prediction.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Class based classification for network intrusion detection

  • Shaoyuan Weng,
  • Xin Gu,
  • Shaleeza Sohail,
  • Fariza Sabrina

摘要

Accurate prediction of intrusion attacks is crucial in the era of Internet of Things to detect and respond promptly to suspicious activities to minimise the damage caused by those attacks. The instances of attacks are always much less than normal traffic and machine learning models are used to detect those comparatively smaller attack classes. For machine learning models the imbalance of classes in the training data results in better accuracy of prediction for majority classes and much less accurate detection of minority classes. In this paper, we propose a class-based classification framework to address the imbalance problem in different categories for network intrusion detection. In the first layer, we train a model for the multi-attack detection and find the class with the best accuracy. Next, the samples labelled as this class are removed while the rest of the data are used to train the model in the next layer. Similar to the previous layer, we train this model for the multi-attack detection and find the class with the best accuracy. This process is repeated until there are only three classes left for training. This model only focuses on the class that has the best performance in each layer. In the prediction phase, we apply the exact matching strategy layer by layer. Once the class is matched, we return the label as the final result; otherwise go to the next layer until a label is matched. The experimental results show that our proposed class-based strategy can improve the performance of the prediction models used. Among all the results, our class-based CatBoost has the best performance in terms of precision, recall, and F1-score where its accuracy is 0.76, the macro average of [precision, recall, F1-score] is [0.75, 0.71, 0.72], and the weighted average of [precision, recall, F1-score] is [0.75, 0.76, 0.75]. These results demonstrated that our class-based technique is effective for multi-attack prediction.