Comparative Analysis of Classifiers for Cyber Attack Prediction on LUflow Dataset with Explainability
Geethika Gunti, Kuruva Divya Sree, Deepa Gupta · 2024
As the cyber threats areevolving, intrusions exploit vulnerabilities in software or systems and can occur 24/7, targeting individuals and organizations.An Intrusion detection system (IDS) is designed to help in the detection of cyberattacks as a part of cybersecurity. Researchers are developing machine learning(ML) based IDS to detect the attacks in a network, and this has proven to be very effective. In this work, we propose a framework using various machine learning classifiers to classify different types of attack classes include benign, malicious and outlier on different sets of LUFlow intrusion detection data. Random Forest and Decision tree have outperformed with an accuracy of 91% on combined year data whileconsidering the individual years data, logistic regression performed less well than all other algorithms including ensemble algorithms.The study includes the examination of precision, recall, and F1 score metrics for each of the employed classification and ensemble methods. Additionally, the most accurate model has been subjected to model interpretability procedures, which have shown the notable characteristics that have a major impact on the categorization of classes.