Presenting an Improved Method for Detecting Computer Attacks Using Feature Reduction Techniques and Machine Learning Algorithms
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Access Rights
Abstract
Experts in computer network security have come to view intrusion detection systems (IDS) as a crucial research topic because of the growing use of computer networks and the corresponding increase in security breaches. In computer network security, the escalating use of computer networks and the corresponding increase in cyberattacks have propelled Intrusion Detection Systems (IDSs) to the forefront of research in computer science. IDSs are a crucial security technology that diligently monitors network traffic and host activities to identify unauthorized or malicious behaviour. In this work, a machine learning algorithm-based approach is presented that can identify, with 100% accuracy, the detection rate of Brute Force type attacks and secure traffic, as well as the detection rate of Bot type attacks with more than 99% accuracy when the fewest identity features are used. Thanks to the CFSSubsetEval feature selection mechanism, this method can use fewer features with the same level of intrusion detection accuracy. Developing an intrusion detection model takes less time than other techniques. Also, this study develops highly accurate models for detecting a diverse range of cyberattacks using the fewest possible features, achieved via a meticulous selection of features. We chose 5, 9, and 10 features, respectively, using the Artificial Bee Colony (ABC), Flower Pollination Algorithm (FPA), and Ant Colony Optimization (ACO) feature-selection techniques. We successfully constructed different models with a remarkable detection accuracy of over 98.8% (approximately 99.0%) with Ant Colony Optimization (ACO), an accuracy of 98.7% with the Flower Pollination Algorithm (FPA) and an accuracy of 98.6% With the Artificial Bee Colony (ABC). Another achievement of this study is the minimum model Building time achieved in intrusion detection, which was equal to 1 s using the Flower Pollination Algorithm (FPA), 2 s using the Artificial Bee Colony (ABC), and 3 s using Ant Colony Optimization (ACO). Our research leverages the comprehensive and up-to-date CSE-CIC-IDS2018 dataset and uses the pre-processing Discretize technique to discretize data. Furthermore, our research provides valuable recommendations to network administrators, aiding them in selecting appropriate machine-learning algorithms tailored to specific requirements. Keywords: machine learning, network security, feature selection, intrusion detection systems, deep learning, cyberattack, computer network, decision tree.
Bilgisayar ağı güvenliği uzmanları, bilgisayar ağlarının artan kullanımı ve buna bağlı olarak güvenlik ihlallerindeki artış nedeniyle izinsiz giriş tespit sistemlerini (IDS) önemli bir araştırma konusu olarak görmeye başladı. Bilgisayar ağı güvenliğinde, bilgisayar ağlarının artan kullanımı ve buna bağlı olarak siber saldırılardaki artış, İzinsiz Giriş Tespit Sistemlerini (IDS'ler) bilgisayar bilimi araştırmalarında ön sıralara taşımıştır. IDS'ler, yetkisiz veya kötü niyetli davranışları belirlemek için ağ trafiğini ve ana bilgisayar etkinliklerini özenle izleyen önemli bir güvenlik teknolojisidir. Bu çalışmada, Brute Force tipi saldırıların ve güvenli trafiğin tespit oranının yanı sıra Bot tipi saldırıların tespit oranını da %99'un üzerinde doğrulukla %100 doğrulukla tespit edebilen, makine öğrenmesi algoritması tabanlı bir yaklaşım sunulmaktadır. en az kimlik özelliği kullanıldığında. CFSSubsetEval özellik seçme mekanizması sayesinde bu yöntem, aynı düzeyde izinsiz giriş tespit doğruluğuyla daha az özellik kullanabilir. Bir saldırı tespit modelinin geliştirilmesi diğer tekniklere göre daha az zaman alır. Ayrıca bu çalışma, çok çeşitli siber saldırıları tespit etmek için mümkün olan en az özelliği kullanarak ve özelliklerin titizlikle seçilmesiyle elde edilen yüksek doğruluklu modeller geliştirmektedir. Yapay Arı Kolonisi (ABC), Çiçek Tozlaşma Algoritması (FPA) ve Karınca Kolonisi Optimizasyonunu kullanarak sırasıyla 5, 9 ve 10 özelliği seçtik. (ACO) özellik seçme teknikleri. Karınca Kolonisi Optimizasyonu (ACO) ile %98,8'in üzerinde (yaklaşık %99,0) dikkate değer bir tespit doğruluğu, Çiçek Tozlaşma Algoritması (FPA) ile %98,7'lik bir doğruluk ve Yapay Arı ile %98,6'lık bir doğrulukla farklı modelleri başarıyla oluşturduk. Koloni (ABC). Bu çalışmanın bir diğer başarısı, Çiçek Tozlaşma Algoritması (FPA) kullanılarak 1 saniyeye, Yapay Arı Kolonisi (ABC) kullanılarak 2 saniyeye ve Karınca Kolonisi Optimizasyonu kullanılarak 3 saniyeye eşit olan izinsiz giriş tespitinde elde edilen minimum model oluşturma süresidir ( AKO). Araştırmamız kapsamlı ve güncel CSE-CIC-IDS2018 veri kümesinden yararlanıyor ve verileri ayrıklaştırmak için ön işleme Ayrıklaştırma tekniğini kullanıyor. Ayrıca araştırmamız ağ yöneticilerine değerli tavsiyeler sunarak onların belirli gereksinimlere göre uyarlanmış uygun makine öğrenimi algoritmalarını seçmelerine yardımcı olur. Anahtar Kelimeler: makine öğrenmesi, ağ güvenliği, özellik seçimi, saldırı tespit sistemleri, derin öğrenme, siber saldırı, bilgisayar ağı, karar ağacı.










