IntruDTree: A Machine Learning Based Cyber Security Intrusion Detection Model

IntruDTree: A Machine Learning Based Cyber Security Intrusion Detection Model
复制标题

DOI:
10.3390/sym12050754
复制
发表时间:
2020-05-01
期刊:
影响因子:
2.7
通讯作者:
Khan, Asif Irshad
Khan, Asif Irshad
中科院分区:
综合性期刊4区
文献类型:
--
作者:
Sarker, Iqbal H.;Abushark, Yoosef B.;Khan, Asif Irshad

文献摘要

被引文献

相似文献

由于物联网(IoT)的普及、计算机网络的巨大增长以及大量的相关应用,网络安全最近在当今的安全问题中受到了极大的关注。因此,检测网络中的各种网络攻击或异常,并建立一个有效的入侵检测系统,在当今的安全中发挥着至关重要的作用,变得越来越重要。人工智能,特别是机器学习技术,可以用于构建这样一个数据驱动的智能入侵检测系统。为了实现这一目标,在本文中,我们提出了一个入侵检测树(“IntruDTree”)的机器学习为基础的安全模型,首先考虑到安全功能的重要性,然后建立一个基于树的广义入侵检测模型的基础上选择的重要功能的排名。该模型不仅在未知测试用例的预测精度方面有效,而且通过减少特征维数来最小化模型的计算复杂度。最后,通过对网络安全数据集进行实验,并计算精确度,召回率,fscore,准确度和ROC值来评估我们的IntruDTree模型的有效性。我们还比较了结果结果的IntruDTree模型与几个传统的流行的机器学习方法,如朴素贝叶斯分类器,逻辑回归,支持向量机,k-最近邻,分析所产生的安全模型的有效性。
Cyber security has recently received enormous attention in today's security concerns, due to the popularity of the Internet-of-Things (IoT), the tremendous growth of computer networks, and the huge number of relevant applications. Thus, detecting various cyber-attacks or anomalies in a network and building an effective intrusion detection system that performs an essential role in today's security is becoming more important. Artificial intelligence, particularly machine learning techniques, can be used for building such a data-driven intelligent intrusion detection system. In order to achieve this goal, in this paper, we present an Intrusion Detection Tree ("IntruDTree") machine-learning-based security model that first takes into account the ranking of security features according to their importance and then build a tree-based generalized intrusion detection model based on the selected important features. This model is not only effective in terms of prediction accuracy for unseen test cases but also minimizes the computational complexity of the model by reducing the feature dimensions. Finally, the effectiveness of our IntruDTree model was examined by conducting experiments on cybersecurity datasets and computing the precision, recall, fscore, accuracy, and ROC values to evaluate. We also compare the outcome results of IntruDTree model with several traditional popular machine learning methods such as the naive Bayes classifier, logistic regression, support vector machines, and k-nearest neighbor, to analyze the effectiveness of the resulting security model.