IDCSNet: Intrusion Detection and Classification System using Unified Gradient-Boosted Decision Tree Classifier

Kondru Mounika, P. Venkateswara Rao · 2022 International Conference on Automation, Computing and Renewable Systems (ICACRS) · 2022

An intrusion detection system (IDS) monitors network traffic for suspicious behavior and alerts the environment. It is software that checks a network or system for potentially dangerous behavior or policy violations. However, the conventional methods failed to detect the malicious activity, which resulted in false alarms. Moreover, the classification of IDS is also quite challenging. Therefore, this work implements an intrusion detection and classification system (IDCS) using a unified gradient-boosted decision tree (GBDT) classifier, hereafter named GBDT-IDS, with preprocessing and data balancing techniques. First, a preprocessing operation is carried out to eliminate the missing symbols, unknown characters, and special letters. Then, the synthetic minority oversampling technique (SMOTE) is used to balance the dataset, which equalizes all the samples of available classes in the dataset. In addition, the balanced dataset is trained with the GBDT-IDS classifier, where GBDT model performance is improved by extreme gradient boosting (XGBoost). Finally, the proposed GBDT-IDS model successfully classifies the denial-of-service (DoS), probe, remote to user (R2U), user to root (U2R) attacks, and normal attacks. The simulation results conducted on the Network Security Laboratory-Knowledge Discovery Databases (NSL-KDD) dataset show that the proposed GBDT-IDS system performs superiorly as compared to the state-of-the-art approaches of IDS.

Read the paper · More papers on PaperTik