Analysis of Traffic Sampling on Machine Learning Based Network Intrusion Detection
A Viksha, Arun Vikas Singh · 2023
A Network-based Intrusion Detection System (NIDS) application monitors traffic flow across the network. A NIDS raises an alarm when an attack or a violation is discovered so that the network administrator can respond appropriately. Network intrusion solutions that rely on machine learning functions using flow characteristics obtained through flow exporting protocols. The applicability of machine learning for NIDS systems assumes that such traffic information is gathered from every packet in the flow. However, in actual use, flow exporters are frequently installed on convenient devices like routers, and switch where processing each flow requires certain bandwidth and memory consumption and thus requires a packet sampling technique. Application of such ML-based NIDS solutions where there is uncertainty in the sampling process. Even in the presence of sampling, it can still offer a reliable assessment of NIDS. Through sampling studies, we can observe that even with low sample rates malignant flows of a smaller size are likely to go undetected. The proposed system indicates a procedure to investigate sampling techniques on NIDS. The detection rate is computed for dynamic sampling rates for a simple random sampling approach, Sketchflow sampling, and hybrid sampling approach by evaluated using Random Forest, Decision Tree, and XGBoost machine learning algorithms. The results of the experiments demonstrate that in comparison to other classifiers Random Forest offers a greater detection rate of 99.3% and a lower false alarm rate through the sampling technique.