Deep Learning-Based Network Intrusion Classification Using Oversampling Methods and Multi-Dataset Validation
| dc.contributor.author | Bhuiyan, Mahbubul Haq | |
| dc.date.accessioned | 2024-11-25T02:00:17Z | |
| dc.date.available | 2024-11-25T02:00:17Z | |
| dc.date.issued | 2024-11-18 | |
| dc.description.abstract | Intrusion detection and classification are crucial for network protection against malware incidents and unauthorized access. Machine Learning and Deep Learning contribute significantly to the enhancement of intrusion detection by recognizing patterns in network traffic data. With techniques of Machine Learning (ML) and Deep Learning (DL), most of the attacks can be detected, even stealthy and polymorphic, which conventional security mechanisms often fail to capture. In this work, we approach the class imbalance problem of the network intrusion detection datasets with data sampling techniques like Adaptive Synthetic Sampling (ADASYN), Synthetic Minority Over-sampling Technique (SMOTE), and Borderline-SMOTE. These algorithms enhance the performance of DL models by improving the accuracy of detecting rare intrusion events. We employ, for that purpose, Deep Neural Networks to raw network data, which proves to be a much better option to classify malicious activities, particularly in large and complex datasets. In such a context, this paper proposes an optimized Deep Neural Network (DNN) model that serves effectively to detect stealthy and polymorphic attacks with high precision. Therefore, the model is trained and tested with the NF-ToN-IoT dataset, while its extended multi-datasets validation is done by testing it on datasets such as NF-BoT-IoT, NF-UNSW-NB15, NF-CSE-CIC-IDS2018, NF-UQ-NIDS, and NF-UNSW-NB15-v2. By doing so, this paper comprehensively discusses the robustness of the model in various network environments. We have also compared our architecture with various state-of-the-art architectures like Convolutional Neural Networks (CNN) with Bidirectional Long ShortTerm Memory (BiLSTM), DNN, Gated Recurrent Units (GRU) with Recurrent Neural Networks (RNN), and CNN with Long Short-Term Memory (LSTM). The proposed model of DNN has performed exceptionally well, reaching a weighted average of 0.99 for all key metrics including accuracy, precision, recall, and F1-score. Besides, the model outperforms the compared architectures and proves its effectiveness for network intrusion classification tasks. The ablation study conducted in this work also presents the influence of some key parameters in the DL model that could be very informative for further studies. | en_US |
| dc.identifier.uri | http://dspace.uiu.ac.bd/handle/52243/3094 | |
| dc.language.iso | en | en_US |
| dc.publisher | UIU | en_US |
| dc.subject | Deep Learning | en_US |
| dc.subject | Intrusion Classification | en_US |
| dc.title | Deep Learning-Based Network Intrusion Classification Using Oversampling Methods and Multi-Dataset Validation | en_US |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Mahbubul Haq Bhuiyan_ID_012 231 0045.pdf
- Size:
- 1.3 MB
- Format:
- Adobe Portable Document Format
- Description:
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.62 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
