A Comparative Study of Five Machine Learning Algorithms for Anomaly-based IDS
Agung Septiadi, Erwin Nashrullah, Muhammad Fauzan Arief, Junanto Prihantoro, Jemie Muliadi, Fatur Rahman Harahap, Kusnanda Supriatna, Aris Suwarjono · 2022
One of the most important devices in cyber security is Intrusion Detection System (IDS). It is a device that is required to be able to monitor network traffic and detect the possibility of intrusion. Anomaly-based IDS is a type of IDS that works by detecting an anomaly in network traffic. The method that is starting to be widely used for detection is machine learning. In this work, the performance of five machine learning algorithm architectures—Decision Tree, ANN, Random Forest, SVM, and Naive Bayes—in an anomaly-based intrusion detection system will be evaluated. Two datasets—KDD Cup 1999 and UNSW-NB15—have been utilized. Before being used, data pre-processing is carried out to reduce the number of features. Our experiment results demonstrate that Random Forest surpassed other algorithms in accuracy, precision and recall on the KDD Cup 1999 dataset, while for the UNSW-NB15 dataset, SVM provides the best performance for all aspects measured.