Intrusion Detection based on clustering with ML algorithm and LIME Insights

Achal Baniya, Abhay Vinod, Hitesh Surya Chinta, Putluru Vishnu, Thangam S · 2024

The threat landscape for cybersecurity is becoming more complex as digital technologies become increasingly sophisticated. Intrusion detection systems (IDS) are required for maintaining the integrity of a network by detecting and neutralizing any attacks. This study investigates how well machine learning (ML) approaches work to strengthen intrusion detection systems (IDS) in the face of changing cyber threats. Since traditional approaches frequently can't keep up with changing attack patterns, ML must be used to improve predictive skills. The IDS purposed clustering technique to identify anomaly behavior within particular groups by classifying network traffic into various patterns. In order to predict anomaly detection, the study investigates the application of various machine learning techniques, such as Random Forest (RF), Adaptive Boosting (AdaBoost), Decision Tree (DT), K-nearest Neighbors (KNN), eXtreme Gradient Boosting (XGBoost), Gaussian Naïve Bayes (GNB), Quadratic Discriminant Analysis (QDA), Linear Discriminant Analysis (LDA), and Logistic Regression (LR). Local Interpretable Model-agnostic Explanations (LIME) is used to determine which features have the biggest impact on a specific prediction. LIME gives insights into the factors that influence the model’s decision. Random Forest and Adaptive Boosting classifiers exhibit superior performance with an accuracy of 99.2% and 98.9%, respectively.

Read the paper · More papers on PaperTik