Hybrid Data Mining Approaches for Intrusion Detection in the Internet of Things
Dijana Oreški, Darko Andročec · 2018
Internet of things devices and services are often not designed with security in mind. For this reason, malicious users can create botnets and other malicious software targeting things' vulnerabilities. In this work, we have tested various data mining techniques and proposed one that gives representing intrusion detection results with small percentage of false positives. Development of a successful prediction model largely depends on data preprocessing phase. Feature reduction implemented as feature extraction or feature selection is main step of preprocessing phase. This paper compares the applications of principal component analysis as feature extraction method and Relief, Information Gain, Gini Index and SfFS as feature selection methods to reduce features for decision tree classification. By examining NSL-KDD data set, the experiment shows that decision trees by feature selection using SfFS can perform significantly better than other approaches.