Comparison of Convolutional Neural Networks, Long Short-Term Memory networks, and Recurrent Neural Networks for Intrusion Detection System
Emmanuel Chinanu Uwazie, Iyere Samuel Iheonkhan, Wasiu Ademola Adenekan, Oghenevovwero Zion Apene · 2024
In recent years, the rapid growth of internet usage has led to an increase in cyber threats and attacks. To combat these threats, the development of effective intrusion detection systems (IDS) has become crucial. In safeguarding computer networks against unauthorized access and malicious activities, intrusion detection systems hold a crucial position. However, traditional rule-based approaches often face challenges in adapting to the continuously evolving cyber threat landscape. Deep learning methodologies, including Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM) networks, and Recurrent Neural Networks (RNNs), have shown encouraging advancements in enhancing the identification and categorization of network intrusions. This paper presents a comparative analysis of these techniques on three well-known intrusion detection datasets: NSL-KDD, CICIDS2017, and CICIDS2018. The aim is to elucidate the strengths and weaknesses of each architecture in detecting network intrusions. For each of the algorithms, different learning rates produced various accuracies on each of the datasets. The learning rate with the highest accuracy for each algorithm is compared with the learning rates with the highest accuracies in other algorithms on the same dataset. The experimental results show that the LSTM Intrusion Detection System outperformed other approaches on all the datasets, with accuracies of 0.997991633, 0.997573678 and 00.97138234 on NSL-KDD, CICIDS2017 and CICIDS2018 datasets, respectively. Consequently, the obtained results of LSTM present better performances in terms of precision, recall and f1-score on the various network traffic classes when compared to the other algorithms. The high performances of these deep learning algorithms show that beyond laboratory experiments, they can be deployed in the field for intrusion detection.