Comparative Evaluation of Network-Based Intrusion Detection: Deep Learning vs Traditional Machine Learning Approach
Miracle Udurume, Vladimir Shakhov, Insoo Koo · 2024
Intrusion detection, a pivotal component of modern cybersecurity, plays a critical role in safeguarding networked systems against unauthorized access and malicious activities. The need for effective intrusion detection intensifies as the digital realm becomes increasingly interconnected. However, the deployment of intrusion detection systems is not without its challenges. The dynamic nature of cyber threats demands adaptive and intelligent detection mechanisms, propelling the exploration of advanced technologies such as deep learning and machine learning models. Balancing the trade-off between accuracy and computational efficiency, interpreting the results of detection algorithms, and handling vast and diverse datasets pose significant challenges that demand complex solutions. This study presents a comprehensive evaluation of the Network Intrusion Detection system, comparing the performance of deep learning vs traditional machine learning models on two benchmark datasets: UNSW-NB15 and NSL-KDD. Deep learning models such as convolutional neural network (CNN) as well as CNN-Bi-directional long short-term memory (CNN-BiLSTM) are examined alongside traditional machine learning algorithms including K-Nearest Neighbors (KNN), Support Vector Machine (SVM), Multilayer Perceptron (MLP), Logistic Regression (LR), Random Forest (RF), and Decision Trees (DT). Performance evaluation metrics such as accuracy, precision, recall, and F1 score are employed to provide a comprehensive understanding of each model's strengths and limitations.