Abstract
Security of information in this Information Technology (IT) era has been one of the challenges facing individuals and organisations. Among the measures developed by security experts to counter security threats is the Intrusion Detection System (IDS). Despite earlier research efforts to develop formidable IDSs, the existing systems still suffer from a high false alarm and inability to detect new (novel) attacks because of the high volume of features in network traffic. Therefore, this study aimed at developing IDS with an enhanced feature selection and classification method using two stages of attack identification. The feature selection phase employed Particle Swarm Optimization (PSO) to optimally select relevant features from Principal Component Analysis (PCA)'s projected principal space. The reduced dataset was passed into the misuse detector using C4.5 to classify network traffic into normal and attack. The "assumed" normal traffic further passed to the anomaly detector, the second-level classifier using Support Vector Machine (SVM) for detecting new attacks that the misuse detector has not previously detected. The proposed model was demonstrated on the KDD Cup’99 and NSL-KDD intrusion datasets, with the system achieving a false alarm rate of 0.53% and detection rate of 99.43% for NSL KDD dataset. The results show that enhancing the feature selection phase and classification method reduces the false alarm and improves the system's ability to detect zero-day attacks.
Author supplied keywords
Cite
CITATION STYLE
Folorunsho, O., Adegbola, I. A., & Jimoh, R. G. (2022). AN ENHANCED FEATURE SELECTION AND CLASSIFICATION MODEL FOR NETWORK INTRUSION DETECTION SYSTEM USING DATA MINING TECHNIQUES. Indian Journal of Computer Science and Engineering, 13(1), 145–156. https://doi.org/10.21817/indjcse/2022/v13i1/221301081
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.