Improving Anomaly Detection in IDS with Hybrid Auto Encoder-SVM and Auto Encoder-LSTM Models Using Resampling Methods

Hesham Mohamed Kamal, Maggie Ezzat Mashaly · 2024

The volume of security threats attempting to compromise systems is increasing as virtualization and information technologies advance. This means that intrusion detection systems (IDSs) play a critical role in network security by helping to identify malicious attacks from network traffic. The most popular machine learning (ML) methods for network anomaly detection, including decision tree (DT), support vector machine (SVM), and k-nearest neighbors (KNN), are based on ML. Even while ML-based IDSs have produced encouraging results and high detection rates, they are still regarded as a form of shallow learning that primarily relies on feature engineering and necessitates extensive data pre-processing as dataset sizes increase. Machine and deep learning-based IDSs are suggested as a solution to these issues because of their superior capacity to extract features from massive volumes of data. In this study, we provide two hybrid auto encoder-long short-term memory (Auto Encoder-LSTM) and auto encoder-support vector machine (Auto Encoder-SVM) learning models that overcomes class imbalance by utilizing data resampling synthetic minority over-sampling technique (SMOTE), edited nearest neighbor (ENN) and class weights. Two hybrid models with an accuracy of 99.6% and 95.01% in binary classification are put forth to detect abnormalities. These models were trained using the CICIDS2017 dataset. The suggested model's superiority over previous models in the literature is then demonstrated by comparing the obtained results with learning techniques as LSTM, SVM, and others.

Read the paper · More papers on PaperTik