Ensemble and Feature Selection-based Intrusion Detection System for Multi-attack Environment

Shraddha R. Khonde, Venugopal Ulagamuthalvi · 2020 5th International Conference on Computing, Communication and Security (ICCCS) · 2020

In the world of internet most challenging issue is to maintain confidentiality and integrity of data. Network provides poor performance in terms of security when it gets compromised by some intruder. Intruders insert intrusions in the network to compromise system and get access to data. To compromise network intrusions are inserted in the form of attack. An attack enters into a network as a normal traffic and then tries to compromise devices connected into network. Now day's intruders are using multi-attacks to break security of network. To detect such type of activities intrusion detection system (IDS) is used. IDS keeps eye on each packet entering into the network. If any abnormal behavior is identified an alert is generated for administrator. However IDS are able to detect only single attack at a time happening on the network. To handle modern era multi-attack improvement in IDS is required. In this paper an improved IDS is presented which can handle multi-attack with the help of machine learning classifiers. Ensemble approach using majority voting algorithm is used for improving performance. To reduce training and computation time feature selection technique is used. Performance evaluation is done using precision, accuracy and false alarm rate. Dataset used for experiments is NSL-KDD. Comparison of individual classifier is done with ensemble approach. Results show that ensemble approach shows reduction of 0.05% in false alarm rate and 2% improvement in accuracy of IDS. Precision of ensemble is also increased by 0.01. Ensemble approach and feature selection provides improved performance of IDS.

Read the paper · More papers on PaperTik