Analyzing Cyber Attacks and Optimizing Performance Metrics through Feature Selection in Intrusion Detection Systems
Navroop Kaur · International Journal of Intelligent Systems and Applications in Engineering · 2024
As cyber threats continue to increase in scale and sophistication, Intrusion Detection Systems (IDS) are essential for protecting modern network infrastructures. This study compares two benchmark datasets—NSL-KDD and CICIDS 2018—to evaluate their effectiveness in modeling intrusion scenarios based on attack diversity, feature richness, and relevance to current threats. While NSL-KDD offers structured and balanced data for traditional attacks, CICIDS 2018 provides realistic traffic with modern threat profiles. A key contribution of this research is the proposal and integration of a new feature—Encrypted Traffic Behavior Analysis—to address the growing use of encrypted communication in cyberattacks. The study further identifies critical features for attack types like DoS, Probe, U2R, and R2L, using methods such as LASSO, PCA, and Mutual Information. A hybrid IDS model leveraging XGBoost is developed and benchmarked against classifiers including Logistic Regression, Naïve Bayes, Decision Tree, Random Forest, SVM, and KNN. Results show high detection accuracy, with XGBoost achieving near-perfect performance by effectively handling high-dimensional, encrypted, and imbalanced data. This demonstrates that combining targeted feature selection with ensemble learning significantly enhances IDS capabilities. Future work will focus on real-time implementation, deep learning integration, and privacy-preserving methods for scalable, intelligent intrusion detection in dynamic environments. DOI: https://doi.org/10.17762/ijisae.v12i22s.7648