Classification of Attacks through the Type of Protocol Using Data Mining
Journal of System and Management Sciences · 2021
Consideration of the security risks in the implementation system must be designed properly.The existence of the intrusion detection system (IDS) will help us classify which one is included in normal access or attack traffic.Therefore, the IDS system itself must always be updated for its database, because the method of attacking a system continues to develop.This study wants to make a comparison of three learning models, Gradient Boosting, Logistic Regression, and Support Vector Machine to classify detection system.The test was carried out using IDS KDD CUP 1999 log, by detecting the access protocol.From the results obtained, SVM is high enough for accuracy, but in fewer class conditions.However when the number of classes increases, SVM processing takes longer than others.Therefore, based on the performance and duration computation, the gradient boosting is outperform than the others.