Feature Ranking and Selection for Intrusion Detection System Using Mathematical Measures
R. Krishna Nayak, Saksham Jain, Anshul Arora · 2024
In the ever-evolving landscape of cybersecurity, the ability to swiftly detect and mitigate intrusions within computer networks is of paramount importance. Intrusion detection serves as a frontline defense mechanism, enabling organizations to safe-guard their sensitive data and critical systems from malicious activities. This research delves into the realm of intrusion detection by employing a comprehensive analysis framework encompassing feature ranking techniques and machine learning algorithms. Leveraging the Dice coefficient, Kendall's tau, and Hamming distance, features crucial for discerning between malware and normal network traffic were identified. The experimental results highlight that when Dice coefficient is applied, the feature Average Packet Sent attains the highest ranking. When Hamming Distance and Kendall's Tau coefficient are employed, the features ratio between incoming and outgoing packets and ratio between incoming and outgoing bytes are considered as the highest-ranked feature respectively. Subsequently, machine learning algorithms such as random forest were employed on the integrated result to further validate the efficacy of the identified features. Through integrated results and experimental validation, it was determined that the average packet size emerges as the most significant determinant feature followed by average packet size, packet size received, ratio between incoming and outgoing bytes, and packet size sent. Our results demonstrate the effectiveness of employing these features along with machine learning techniques for accurate intrusion detection. This research contributes to an advanced intrusion detection system, providing insightful information to strengthen network security against evolving cyber threats.