<p>The detection of malicious activity in network systems on the basis of network traffic analysis involves machine learning and optimization algorithms are growing widely in engineering applications of intrusion detection systems. In this article, a meta-heuristic approach with ensemble learning algorithm LightGBM is applied to detect the malicious activity in network traffic. Since efficient intrusion detection in network traffic involves selection of relevant and important features. The proposed GWO-LGBM based methodology outperforms these feature selection and evaluation criteria with strong intrusion detection capabilities even in the presence of huge network traffic scenario. For performances evaluation, we have used a range of comprehensive assessment measures, such as testing accuracy, training accuracy, recall, precision, F1-score, MCC-score, log-loss, computation time, and characteristics picked for detection. With this approach, we obtained more than 99% each for accuracy, recall, precision, F1- score, and MCC-score The computational time, features, and log loss have been observed as 27.737 secs, 20 and 99E-16 respectively for UNSW-NB15 dataset. Similarly, for CIRA_CIC_DoHRrW dataset best, we again obtained more than 99% of accuracy, recall, precision, F1-score, and MCC-score of 99.99% with only 11 features, negligible 99E-16 log-loss and 44.66 secs of computational time. And for BoT-IoT dataset, we also obtain more than 99% of accuracy, recall, precision, F1-score and MCC-score with 15 features, negligible 0.057 log-loss and 1.40 secs execution time. </p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ensemble based meta-heuristic optimized approach for network intrusion detection using LightGBM

  • Sandeep Mahato,
  • Subrata Dutta

摘要

The detection of malicious activity in network systems on the basis of network traffic analysis involves machine learning and optimization algorithms are growing widely in engineering applications of intrusion detection systems. In this article, a meta-heuristic approach with ensemble learning algorithm LightGBM is applied to detect the malicious activity in network traffic. Since efficient intrusion detection in network traffic involves selection of relevant and important features. The proposed GWO-LGBM based methodology outperforms these feature selection and evaluation criteria with strong intrusion detection capabilities even in the presence of huge network traffic scenario. For performances evaluation, we have used a range of comprehensive assessment measures, such as testing accuracy, training accuracy, recall, precision, F1-score, MCC-score, log-loss, computation time, and characteristics picked for detection. With this approach, we obtained more than 99% each for accuracy, recall, precision, F1- score, and MCC-score The computational time, features, and log loss have been observed as 27.737 secs, 20 and 99E-16 respectively for UNSW-NB15 dataset. Similarly, for CIRA_CIC_DoHRrW dataset best, we again obtained more than 99% of accuracy, recall, precision, F1-score, and MCC-score of 99.99% with only 11 features, negligible 99E-16 log-loss and 44.66 secs of computational time. And for BoT-IoT dataset, we also obtain more than 99% of accuracy, recall, precision, F1-score and MCC-score with 15 features, negligible 0.057 log-loss and 1.40 secs execution time.