Voting Ensemble: Performance Improvement for Intrusion Detection System

C. Rajathi, P. Rukmani · 2024

In the present digital world, security has become increasingly challenging. Many organizations rely on security mechanisms to safeguard their resources from intrusion. However, previous research indicates that despite the implementation of several security measures, organizations still face security breaches. Therefore, organizations must adopt an effective security mechanism. One such mechanism is the Intrusion Detection System (IDS), which examines network traffic to protect an organization from potential attacks. To handle the large volume of network traffic, a well-organized classification system is necessary. Machine learning classification, among the various approaches used in research, provides an effective and efficient solution for detecting intrusion and enhancing security. Despite significant efforts, IDS still faces challenges due to the nature of the concept drifting. To mitigate this issue, a hybrid ensemble approach is proposed. This approach combines the Majority Rule Ensemble (MRE) and Probability Consensus Ensemble (PCE). The ensemble is constructed using various classification algorithms such as Logistic Regression (LR), Naive Bayes (NBC), K-Nearest Neighbor (KNN), Support Vector Machine (SVM), Decision Tree (DT), and Random Forest (RF). Each algorithm was individually built on the training dataset. The hybrid ensemble, which employs the MRE and PCE as aggregation methods, is then prepared by fitting it to the dataset. The proposed model’s effectiveness is assessed using Network Security Laboratory – Knowledge Discovery and Databases (NSL-KDD) and a real-time testbed dataset. The results from the proposed hybrid ensemble show the improvement in the model’s performance and the adaptability to the drifting nature of the intrusion dataset compared to a standalone model.

Read the paper · More papers on PaperTik