Applying a Machine Learning Framework to Improve the Efficacy of Network Intrusion Detection Systems

Abdullah, Anil Kumar, Kadim A. Jabbar, Mohammed Yousif Oudah, Abdul Azeem Khan, Rajan Verma · 2024

Intrusion Detection Systems (IDS) play a vital role in spotting aberrant traffic and analyzing large amounts of data, especially during Distributed Denial of Service (DDoS) assaults. To ensure an IDS operates at peak performance, a reliable traffic classification approach is required. The objective of this research is to identify the most effective machine learning technique for enhancing system accuracy from the three available options: Support Vector Machine (SVM), Decision Jungle (DJ), and Random Forest (RF). Reducing the number of false alarms while increasing the number of correct ones is the goal. The primary objectives of this research are to create a machine learning model for a network intrusion detection system and to evaluate the performance of three algorithms in detecting suspicious network activities. As a standard for assessing IDSs, the study uses the Intrusion Detection Evaluation Dataset in conjunction with the KDD approach. The SVM outperforms DJ (96.50%) and RF (96.76%) with an average accuracy of 98.18%. Similarly, SVM surpasses RF with a precision of 97.96% and DJ with a precision of 97.82%, achieving an average precision of 98.74%. RF outperforms SVM (95.63%) and DJ (95.77%) in terms of average recall, with the highest value of 97.62%. Ultimately, the SVM algorithm has the highest level of performance in the system for detecting intrusions.

Read the paper · More papers on PaperTik