Machine Learning and Ensemble Learning Techniques for Intrusion Detection Systems: A Performance Analysis Based on Feature Selection Methods
Tarih
Yazarlar
Dergi Başlığı
Dergi ISSN
Cilt Başlığı
Yayıncı
Erişim Hakkı
Özet
Anomaly-based intrusion detection systems rely on analyzing the behavior of data within the network. In such systems, the imperative lies in crafting designs that employ a minimal yet effective set of features. This approach facilitates the creation of systems that operate with enhanced speed and accuracy rates. This study utilized the UNR-IDD dataset, a representative intrusion detection dataset employing Network Port Statistics. UNR-IDD encompasses six distinct data classes, including five different attack types and normal data samples. The identification of the most significant features in the dataset are carried out through the application of Least Absolute Shrinkage and Selection Operator (LASSO), Laplacian Score, Correlation Based Feature Selection (CFS), and ReliefF feature selection techniques. Subsequently, based on the identified features, a variety of machine learning classifiers, namely Decision Tree (DT), Random Forest (RF), Logistic Regression (LR), Support Vector Machine (SVM), Multi-Layer Perceptron (MLP), Naive Bayes (NB), as well as ensemble learning techniques including CatBoost, Gradient Boosting, XGBoost, AdaBoost (ADA), Voting, and Stacking, are employed. The performance of related machine learning and ensemble learning techniques are compared, and metrics such as accuracy, precision, recall, and F1-score are presented considering 80% training rate. The highest accuracy, reaching 97.1% for an 80% training rate, is achieved when 25 of 34 features are selected using the Laplacian Score feature selection technique, coupled with the application of the Stacking ensemble learning approach.










