Attack Classification using Machine Learning on UNSW-NB 15 dataset using XGBoost Feature Selection & Ablation Analysis

Nikunj Pansari, Shourya Srivastava, Raghu Raghavendra, Mayank Agarwal · 2024

The surge in network intrusions is a pressing concern for industry and government in cybersecurity. To counter this, network intrusion detection systems (NIDS) discern normal and abnormal network traffic effectively. Accurate anomaly identification depends on NIDS precision and performance metrics. Diverse feature selection methods, including standard, ensemble, and hybrid strategies, have been adopted to bolster intrusion detection datasets. In this study, we explore the application of the XGBoost feature selection technique on the UNSW-NB15 dataset. The core objective of our feature selection approach is to identify the optimal number of features conducive to the analysis of attacks, catering to both binary and multi-class classification scenarios. Subsequently, we meticulously assess the performance of diverse machine learning algorithms. This comprehensive evaluation includes well-known methods such as logistic regression, KNN, random forest, Decision Tree, AdaBoost, Bagging, and J48. Our scrutiny extends to another facet, wherein we conduct an ablation study. Specifically, we systematically eliminate the minority attack classes, namely Worms and Shellcode, separately from the training and test sets. The results with the reduced feature set provided better accuracy, precision, recall, and F1-Score compared to preceding rudimentary implementations. More specifically the training and testing time showed an improvement of over 50% in most cases under ablation with a reduced feature set using XGBoost (N =19) features while still retaining a higher accuracy score obtained with all features under consideration (N = 41).

Read the paper · More papers on PaperTik