Deep Learning-Based Network Intrusion Classification Using Oversampling Methods and Multi-Dataset Validation

dc.contributor.authorBhuiyan, Mahbubul Haq
dc.date.accessioned2024-11-25T02:00:17Z
dc.date.available2024-11-25T02:00:17Z
dc.date.issued2024-11-18
dc.description.abstractIntrusion detection and classification are crucial for network protection against mal￾ware incidents and unauthorized access. Machine Learning and Deep Learning contribute significantly to the enhancement of intrusion detection by recognizing patterns in network traffic data. With techniques of Machine Learning (ML) and Deep Learning (DL), most of the attacks can be detected, even stealthy and polymorphic, which conventional se￾curity mechanisms often fail to capture. In this work, we approach the class imbalance problem of the network intrusion detection datasets with data sampling techniques like Adaptive Synthetic Sampling (ADASYN), Synthetic Minority Over-sampling Technique (SMOTE), and Borderline-SMOTE. These algorithms enhance the performance of DL models by improving the accuracy of detecting rare intrusion events. We employ, for that purpose, Deep Neural Networks to raw network data, which proves to be a much better option to classify malicious activities, particularly in large and complex datasets. In such a context, this paper proposes an optimized Deep Neural Network (DNN) model that serves effectively to detect stealthy and polymorphic attacks with high precision. Therefore, the model is trained and tested with the NF-ToN-IoT dataset, while its ex￾tended multi-datasets validation is done by testing it on datasets such as NF-BoT-IoT, NF-UNSW-NB15, NF-CSE-CIC-IDS2018, NF-UQ-NIDS, and NF-UNSW-NB15-v2. By doing so, this paper comprehensively discusses the robustness of the model in various net￾work environments. We have also compared our architecture with various state-of-the-art architectures like Convolutional Neural Networks (CNN) with Bidirectional Long Short￾Term Memory (BiLSTM), DNN, Gated Recurrent Units (GRU) with Recurrent Neural Networks (RNN), and CNN with Long Short-Term Memory (LSTM). The proposed model of DNN has performed exceptionally well, reaching a weighted average of 0.99 for all key metrics including accuracy, precision, recall, and F1-score. Besides, the model outperforms the compared architectures and proves its effectiveness for network intrusion classification tasks. The ablation study conducted in this work also presents the influence of some key parameters in the DL model that could be very informative for further studies.en_US
dc.identifier.urihttp://dspace.uiu.ac.bd/handle/52243/3094
dc.language.isoenen_US
dc.publisherUIUen_US
dc.subjectDeep Learningen_US
dc.subjectIntrusion Classificationen_US
dc.titleDeep Learning-Based Network Intrusion Classification Using Oversampling Methods and Multi-Dataset Validationen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Mahbubul Haq Bhuiyan_ID_012 231 0045.pdf
Size:
1.3 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.62 KB
Format:
Item-specific license agreed upon to submission
Description: