Stacked HRDGL: A Fast Hybrid Model for Real-Time Network Intrusion Detection

Rana Muhammad Rashid, Hira Khyzer, Xun Yijie · 2024

The increasing sophistication of network attacks, such as Distributed Denial of Service (DDoS) and darknet traffic anomalies, necessitates more efficient real-time network intrusion detection systems (NIDS). XGBoost has become a popular baseline for intrusion detection due to its high accuracy, but its latency often falls short of real-time requirements. In this work, we introduce Stacked HRDGL, a novel dynamic hybrid ensemble model that optimizes both detection accuracy and latency by leveraging a diverse set of base learners and an innovative stacking mechanism. The model combines Logistic Regression, Naive Bayes, Decision Tree, and Random Forest, selected for their complementary strengths in handling linearity, probabilistic inference, and decision boundaries, which collectively improve classification robustness. The novelty of Stacked HRDGL lies in its optimized stacking structure, which minimizes inter-model redundancy and enhances meta-learner decision-making, resulting in superior detection speed without compromising accuracy. Evaluated on the CICIDS2017 and CICDarknet2020 datasets for DDoS and darknet anomaly detection, Stacked HRDGL achieves competitive accuracy (99.98% on CICIDS2017 and 94.03% on CICDarknet2020), while significantly reducing latency by up to 15x compared to XGBoost, as measured on a standard multicore system. Although tested primarily on these two datasets, Stacked HRDGL's flexible architecture suggests scalability across diverse network traffic types and evolving threats. The model's low resource footprint and efficient execution make it particularly suited for real-time deployment in high-traffic environments. This paper contributes a practical, scalable solution to the NIDS field, bridging the gap between accuracy and real-time performance with an innovative ensemble approach.

Read the paper · More papers on PaperTik