Effective Intrusion Detection in High-Class Imbalance Networks Using Consolidated Tree Construction

Ranjit Panigrahi, Samarjeet Borah, Akash Kumar Bhoi · 2024

In the advent of information communication technology worldwide, the greatest challenge that the network engineers facing today is the identification of malevolent activities in a system or in a network. The intrusion detection systems (IDSs) play a crucial role in minimizing such kind of activities. Unfortunately, most of the IDS suffer devastating number of false alarms both for known and unknown attacks, as the detection model is trained on high-class imbalance dataset. This issue is incredibly challenging to solve even for the networks of nominal size. Many procedures to collect, aggregate, associate, and classify the traffic messages have already been proposed but with invoking many challenges and open areas of research. This chapter addresses the challenge of network attacks an IDS has been proposed in this chapter. The proposed IDS engine was evaluated using the CICIDS2017 dataset, which includes benign and 14 attack classes. Handling this large dataset with over 2.8 million instances and 85 features while addressing high-class imbalance required a multi-step approach. We ranked features using an infinite latent feature selection method, performed sampling using Reservoir sampling for equal probability inclusion, and generated test cases with Stratified Remove Folds (SRF) from Weka simulator. In the detection phase, our C45-based classification mechanism, J48Consolidated, empowered with the consolidated tree construction (CTC) algorithm, achieved a remarkable 97.12% threat detection accuracy, with a low misclassification rate of 2.87% and minimal false alarms at 0.002%. This IDS engine offers an effective solution for high-class imbalance scenarios, making it a valuable tool in cybersecurity.

Read the paper · More papers on PaperTik