Feature Reduction in Flow Based Intrusion Detection System

Gayatri Patil, Vinod Pachghare, Deepak D. Kshirsagar · 2018

Intrusion Detection System (IDS) is a component which monitors the traffic and analyzes it. It helps in detection of malicious traffic and intrusions and security attacks. Developing IDS to get better accuracy with reduced false positive rate is the important factor. Moreover, the amount of data to be analyzed is beyond the ability of commonly used computer hardware and software tools. And it takes lots of time for processing of such huge network traffic. So, one must find an efficient way to reduce the size of data from dataset without losing important and relevant information. In this paper we proposed a feature selection for effective Intrusion Detection System. The proposed system performs feature selection. In this paper, we proposed a performance based feature selection process with machine learning for most relevant features selection. We used JRip rule based classification algorithm for performance evaluation using 10-fold cross validation. This study is performed using a new labeled flow based CICIDS2017 data set. There are total 85 features in CICIDS2017 data set. In this paper we focused on relevant feature selection for DDoS LOIC (Low Orbit Ion Cannon) attack. Out of total 86 features we find 18 most relevant features subset for DDoS LOIC attack which gave more accuracy and reduced processing time. The proposed system along with only most relevant features set helps in developing IDS accuracy and reducing computation time.

Read the paper · More papers on PaperTik