Enhancing Intrusion Detection Systems with Deep Learning and Machine Learning Algorithms for Real-Time Threat Classification
Rahul Vadisetty, Anand Polamarasetti · 2024
Computer network intrusion has surged dramatically over the past decade, fueled by a lucrative underground cybercrime economy and the proliferation of sophisticated tools for executing such attacks. For over forty years, researchers from both industry and academia have been developing methods and systems to detect and prevent these security breaches. Machine learning (ML) techniques have emerged as a powerful tool among the various methods used to classify normal and abnormal behaviour. This study presents an advanced preprocessing strategy combined with a comprehensive evaluation of traditional machine learning models and a deep neural network (DNN) for real-time network intrusion detection. Preprocessing includes univariate analysis, feature selection, outlier handling, data normalization, and PCA-based dimensionality reduction. Further, the dataset was divided into train and test sets in the ratio 80:20. Traditional models GB, DT, and ET have been tested; however, ET performs better than all concerning accuracy, precision, recall, F1 score, and kappa. The proposed DNN model further enhanced detection capabilities, achieving the highest metrics across all evaluation parameters, including an AUC of 1.00, an accuracy of $99.50 \%$ and the lowest misclassification rate. The performance of both traditional and deep learning models was assessed using precision, recall, kappa, accuracy, F1 score, ROC curve analysis, and confusion matrices. The results indicate that the proposed approach is efficient for real-time network intrusion detection and threat analysis.