Analysis and Comparison of Raw Network Packet Datasets Using Machine Learning Classification and Grey Wolf Optimization
Hussein Ahmad Al-Ofeishat, Jawdat S. Alkasassbeh, Albara W. Awajan, Moutaz Alazab · International Journal of Advances in Soft Computing and its Applications · 2025
A Machine Learning (ML)- Driven automatic defense mechanism has become an efficient way to safeguard organizations from massive volumes of intrusions executed in random patterns. A successful defense against a cyber-attack reveals the ineffective nature of the intrusion on the target network, which guides the intruders in modifying their methods. This ever-evolving dynamics of cyber-attacks necessitate frequent analysis of the effectiveness of the existing ML models against different types of intrusions. This paper presents an exploratory analysis of the effectiveness of ten ML models in various settings to defend against cyber-attacks performed using the UNSW-NB15 dataset. This analysis involves an innovative integration of the Grey Wolf Optimization (GWO) algorithm to reduce the feature vector of the dataset by using the features with strong correlation with the target variables. The exploratory analysis of this study finds the Random Forest and Extra Trees models to be the most accurate, with 97.68% and 97.53%, respectively, along with the Fact sheet showing an increase in the performance ratio of the Random Forest model reaching a very high level of 98.25%, followed by the success rate of Extra Trees model which reached 98.17%. GWO efficiently reduces the feature set from 39 to 20 to improve the model performance and reduce computational time. The findings of this study lay the groundwork for researchers and developers intending to apply ML models to defend against cyber-attacks automatically.