Detecting Web Attacks in Severely Imbalanced Network Traffic Data

Richard Zuech, John Hancock, Taghi M. Khoshgoftaar · 2021

Class imbalance is an important consideration for cybersecurity and machine learning. We explore classification performance in detecting web attacks from the recent CSE-CIC-IDS2018 dataset with class imbalance in mind. The Area Under the Receiver Operating Characteristic Curve (AUC) metric is utilized for classification performance with three ensemble-based classifiers: Random Forest, LightGBM, and XGBoost. We evaluate whether applying random undersampling (RUS) helps these classifiers, and yes applying RUS improves performance in a statistically significant manner in terms of AUC. These ensemble learners fare poorly until massive RUS is applied to this severely imbalanced dataset. Our unique data preparation of CSE-CID-IDS2018 affords a harsh experimental testbed of class imbalance as encountered in the real world for cybersecurity attacks. To the best of our knowledge, we are the first to apply random undersampling techniques to web attacks from the CSE-CIC-IDS2018 dataset exploring various sampling ratios.

Read the paper · More papers on PaperTik