Interpreting Intrusion Detection Features using Coalition-based Game Theory and Machine Learning
M. C. Nidhisheshwin, S. Shreeshaa, J. V. Anand · 2025
The core idea behind this research with the intrusion detection dataset is to incorporate game theory with machine learning models in CSE CIC-IDS2018 dataset. Two application layer attacks, namely DoS Goldeneye and DoS HULK, are taken from the labelled dataset excluding the timestamps and the remaining 78 features are used for analysis. Both attacks use the Hyper Text Transfer Protocol (HTTP) with different request patterns. The request pattern involving the DoS Goldeneye is slow, whereas the DoS HULK uses aggressive request patterns sent at irregular intervals. Incorporating random forest with feature importance selects the most influential five features among the 78 features in each of the attack dataset. Training followed by testing the model with kNN and Decision tree classifier is done for evaluation of indices accuracy, precision, Recall and F1 Score. The results indicate the selected feature contribute more in predicting the target attack class. The results are visualization using a waterfall plot and a summary plot for each attack class.