Cyberthreat Real-time Detection Based on an Intelligent Hybrid Network Intrusion Detection System
Said Ouiazzane, Malika Addou, Fatimazahra Barramou · River Publishers eBooks · 2023
Cybercrime continues to threaten the security of web-connected information systems. Moreover, information is becoming more and more valuable and is the heritage of every size organization operating in all areas of expertise. Therefore, implementing an intrusion detection system is now mandatory to monitor network events and anticipate security incidents that would be costly for the affected organizations. In this work, we have proposed a hybrid, intelligent, cooperative, and distributed network intrusion detection system (KIDS) capable of detecting any type of intrusion that may target modern computer networks. Our system comprises two parts: the first part provides anomaly detection using artificial intelligence and the second part detects known cyber-attacks. Anomaly detection was performed by modeling the network baseline during the normal operation of the network using the decision tree (DT) algorithm applied to the CICIDS2017 dataset. The used dataset underwent pre-processing actions, including eliminating infinite, missing, and duplicate values and reducing dimensionality to retain only the most relevant attributes. Consequently, the DT recognized normal network traffic with up to 99.9% of 176accuracy and a very low false alarm rate. In addition, Suricata has been used to detect known cyber-attacks, thanks to its multi-threaded functionality. The proposed hybrid system recognized deviations from the baseline and performed well in detecting known attacks with a higher accuracy and a low false alarm rate.