scholarly journals Network intrusion detection: a comparative study of four classifiers using the NSL-KDD and KDD’99 datasets

2022 ◽  
Vol 2161 (1) ◽  
pp. 012043
Author(s):  
Ananya Devarakonda ◽  
Nilesh Sharma ◽  
Prita Saha ◽  
S Ramya

Abstract As most of the population acquires access to the internet, protecting online identity from threats of confidentiality, integrity, and accessibility becomes an increasingly important problem to tackle. By definition, a network intrusion detection system (IDS) helps pinpoint and identify anomalous network traffic to bring forward and classify suspicious activity. It is a fundamental part of network security and provides the first line of defense against a potential attack by alerting an administrator or appropriate personnel of possible malicious network activity. Several academic publications propose various artificial intelligence (AI) methods for an accurate network intrusion detection system (IDS). This paper outlines and compares four AI methods to train two benchmark datasets- the KDD’99 and the NSL-KDD. Apart from model selection, data preprocessing plays a vital role in contributing to accurate solutions, and thus, we propose a simple yet effective data preprocessing method. We also evaluate and compare the accuracy and performance of four popular models- decision tree (DT), multi-layer perceptron (MLP), random forest (RF), and a stacked autoencoder (SAE) model. Of the four methods, the random forest classifier showed the most consistent and accurate results.

2018 ◽  
Vol 5 (3) ◽  
pp. 71-88
Author(s):  
Sireesha Rodda ◽  
Uma Shankar Erothi

Designing an effective network intrusion detection system is becoming an increasingly difficult task as the sophistication of the attacks have been increasing every day. Usage of machine learning approaches has been proving beneficial in such situations. Models may be developed based on patterns differentiating attack traffic from network traffic to gain insight into the network activity to identify and report attacks. In this article, an ensemble framework based on roughsets is used to efficiently identify attacks in a multi-class scenario. The proposed methodology is validated on benchmark KDD Cup '99 and NSL_KDD network intrusion detection datasets as well as six other standard UCI datasets. The experimental results show that proposed technique RST achieved better detection rate with low false alarm rate compared to bagging and RSM.


2020 ◽  
Vol 38 (1B) ◽  
pp. 6-14
Author(s):  
ٍٍSarah M. Shareef ◽  
Soukaena H. Hashim

Network intrusion detection system (NIDS) is a software system which plays an important role to protect network system and can be used to monitor network activities to detect different kinds of attacks from normal behavior in network traffics. A false alarm is one of the most identified problems in relation to the intrusion detection system which can be a limiting factor for the performance and accuracy of the intrusion detection system. The proposed system involves mining techniques at two sequential levels, which are: at the first level Naïve Bayes algorithm is used to detect abnormal activity from normal behavior. The second level is the multinomial logistic regression algorithm of which is used to classify abnormal activity into main four attack types in addition to a normal class. To evaluate the proposed system, the KDDCUP99 dataset of the intrusion detection system was used and K-fold cross-validation was performed. The experimental results show that the performance of the proposed system is improved with less false alarm rate.


Sign in / Sign up

Export Citation Format

Share Document