File Download

  • Find it @ UNIST can give you direct access to the published full text of this article. (UNISTARs only)
Related Researcher

MarcoComuzzi

Comuzzi, Marco
Intelligent Enterprise Lab.
Read More

Views & Downloads

Detailed Information

Cited time in webofscience Cited time in scopus
Metadata Downloads

TSE-IDS: A Two-Stage Classifier Ensemble for Intelligent Anomaly-based Intrusion Detection System

Author(s)
Tama, Bayu AdhiComuzzi, MarcoRhee, Kyung-Hyune
Issued Date
2019-07
DOI
10.1109/access.2019.2928048
URI
https://scholarworks.unist.ac.kr/handle/201301/27018
Fulltext
https://ieeexplore.ieee.org/document/8759867
Citation
IEEE ACCESS, v.7, pp.94497 - 94507
Abstract
Intrusion detection systems (IDS) play a pivotal role in computer security by discovering and repealing malicious activities in computer networks. Anomaly-based IDS, in particular, rely on classification models trained using historical data to discover such malicious activities. In this paper, an improved IDS based on hybrid feature selection and two-level classifier ensembles is proposed. An hybrid feature selection technique comprising three methods, i.e. particle swarm optimization, ant colony algorithm, and genetic algorithm, is utilized to reduce the feature size of the training datasets (NSL-KDD and UNSW-NB15 are considered in this paper). Features are selected based on the classification performance of a reduced error pruning tree (REPT) classifier. Then, a two-level classifier ensembles based on two meta learners, i.e., rotation forest and bagging, is proposed. On the NSL-KDD dataset, the proposed classifier shows 85.8% accuracy, 86.8% sensitivity, and 88.0% detection rate, which remarkably outperform other classification techniques recently proposed in the literature. Results regarding the UNSW-NB15 dataset also improve the ones achieved by several state of the art techniques. Finally, to verify the results, a two-step statistical significance test is conducted. This is not usually considered by IDS research thus far and, therefore, adds value to the experimental results achieved by the proposed classifier.
Publisher
Institute of Electrical and Electronics Engineers Inc.
ISSN
2169-3536
Keyword (Author)
hybrid feature selectionintrusion detection systemstatistical significance testTwo-stage meta classifiernetwork anomaly detection
Keyword
MACHINEINTERNETTHINGSSECURITYFORESTMODEL

qrcode

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.