Network Data Classification Mechanism for Intrusion Detection System

Shuai Jiang, Xiaolong Xu · 2021

Intrusion detection system (IDS), as a network security device, monitors network data in real time and responds actively when it detects suspicious transmissions. However, suffered from the large amount of redundancy and high correlation of network data, the traditional IDS have defects in low detection rate and high computational overhead. In this paper, we propose a network data classification mechanism (CPEL). Data preprocessing of network traffic data is first performed using correlation-based feature selection (CFS) and principal component analysis (PCA). CFS selects the best features in the data, PCA to dimensionality reduction and denoising. Then, we use multiple classifiers to perform anomaly detection, and select the best three classifiers according to the classification effect. On this basis, we use the majority vote as the ensemble learning (EL) method of combination rules to further improve the performance of the classifier. Experimental results on the benchmark NSL-KDD and WSN-DS datasets indicate that this mechanism outperforms a single algorithm in accuracy and detection rate. In the meantime, computational overhead is remarkably reduced.

Read the paper · More papers on PaperTik