Enhancing Network Anomaly Detection with Optimized One-Class SVM (OCSVM)
Sahrul Mulia Siregar, Yudha Purwanto, Suryo Adhi Wibowo · 2023
In recent years, the proliferation of cyber threats has propelled the adoption of machine learning techniques in Intrusion Detection Systems (IDS). As the frequency and sophistication of cyber attacks continue to escalate, the demand for effective and intelligent intrusion detection solutions has never been greater. Unsupervised machine learning methods have gained prominence in the IDS domain due to their ability to detect both known and unknown attack types, including zero-day attacks. This paper presents a novel approach that optimizes One-Class Support Vector Machine (OCSVM) algorithms to identify previously unknown cyber threats. The proposed methodology is rigorously evaluated using the CIC-IDS2017 dataset, a widely recognized benchmark in intrusion detection research. A critical aspect of the approach involves feature selection, KBest method used to improve anomaly detection. On this research, we compare OCSVM with KBest - 15 features, OCSVM with KBest - 25 features, and OSCVM without feature selection. The research results show OCSVM with KBest - 15 features has the best metric with an accuracy of 0.9992, 0.9996, 0.9991, and 0.9996 for scenarios. In addition, based on this simulation it can also be concluded that the duration of training and testing processing is effectively reduced by the amount of selected dataset features.