CORTEXA
← Browse
crossrefFuture Internet2020-09-30Cited by 101

Comparison of Machine Learning and Deep Learning Models for Network Intrusion Detection Systems

Niraj Thapa, Zhipeng Liu, Dukka B. KC, Balakrishna Gokaraju, Kaushik Roy

The development of robust anomaly-based network detection systems, which are preferred over static signal-based network intrusion, is vital for cybersecurity. The development of a flexible and dynamic security system is required to tackle the new attacks. Current intrusion detection systems (IDSs) suffer to attain both the high detection rate and low false alarm rate. To address this issue, in this paper, we propose an IDS using different machine learning (ML) and deep learning (DL) models. This paper presents a comparative analysis of different ML models and DL models on Coburg intrusion detection datasets (CIDDSs). First, we compare different ML- and DL-based models on the CIDDS dataset. Second, we propose an ensemble model that combines the best ML and DL models to achieve high-performance metrics. Finally, we benchmarked our best models with the CIC-IDS2017 dataset and compared them with state-of-the-art models. While the popular IDS datasets like KDD99 and NSL-KDD fail to represent the recent attacks and suffer from network biases, CIDDS, used in this research, encompasses labeled flow-based data in a simulated office environment with both updated attacks and normal usage. Furthermore, both accuracy and interpretability must be considered while implementing AI models. Both ML and DL models achieved an accuracy of 99% on the CIDDS dataset with a high detection rate, low false alarm rate, and relatively low training costs. Feature importance was also studied using the Classification and regression tree (CART) model. Our models performed well in 10-fold cross-validation and independent testing. CART and convolutional neural network (CNN) with embedding achieved slightly better performance on the CIC-IDS2017 dataset compared to previous models. Together, these results suggest that both ML and DL methods are robust and complementary techniques as an effective network intrusion detection system.

View free PDFSource page

Related papers

crossrefFuture Internet2021-04-28Cited by 260

Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks

Abdulsalam O. Alzahrani, Mohammed J. F. Alenazi

Software-defined Networking (SDN) has recently developed and been put forward as a promising and encouraging solution for future internet architecture. Managed, the centralized and controlled network has become more flexible and visible using SDN. On the other hand, these advanta…

View free PDFSource page
crossrefFuture Internet2023-08-14Cited by 10

Enhancing Network Security: A Machine Learning-Based Approach for Detecting and Mitigating Krack and Kr00k Attacks in IEEE 802.11

Zaher Salah, Esraa Abu Elsoud

The rise in internet users has brought with it the impending threat of cybercrime as the Internet of Things (IoT) increases and the introduction of 5G technologies continues to transform our digital world. It is now essential to protect communication networks from illegal intrusi…

View free PDFSource page
crossrefFuture Internet2023-08-19Cited by 24

An Improved Deep Learning Model for DDoS Detection Based on Hybrid Stacked Autoencoder and Checkpoint Network

Amthal K. Mousa, Mohammed Najm Abdullah

The software defined network (SDN) collects network traffic data and proactively manages networks. SDN’s programmability makes it excellent for developing distributed applications, cybersecurity, and decentralized network control in multitenant data centers. This exceptional arch…

View free PDFSource page
crossrefFuture Internet2024-05-12Cited by 23

Evaluating Realistic Adversarial Attacks against Machine Learning Models for Windows PE Malware Detection

Muhammad Imran, Annalisa Appice, Donato Malerba

During the last decade, the cybersecurity literature has conferred a high-level role to machine learning as a powerful security paradigm to recognise malicious software in modern anti-malware systems. However, a non-negligible limitation of machine learning methods used to train…

View free PDFSource page
crossrefFuture Internet2026-04-27Cited by 1

Enhancing Network Intrusion Detection with Quantum Machine Learning: A Comprehensive Survey of Methods, Metrics, and Applications

Antanios Kaissar, Ali Bou Nassif, Ahmed Bouridane

Quantum computing introduces new computational capabilities that can support advanced cybersecurity solutions when combined with machine learning. In recent years, quantum machine learning (QML) has emerged as a promising approach for enhancing network intrusion detection systems…

View free PDFSource page