Intrusion detection and classification using deep belief networks with feature reduction
摘要
Cybersecurity threats are becoming more sophisticated with the emergence of networks and businesses’ reliance on connectivity. The cyberattacks require continuous upgradation of intrusion detection systems (IDS) to counter these ever-changing attacks to maintain integrity, availability, and confidentiality. Despite substantial research, an IDS requires continuous signature updates and ample prediction time. IDS must focus on detecting novel intrusions and improving detection accuracy while lowering false alarm rates. This study proposed a layered optimized deep belief network (DBN) with feature reduction using principal component analysis (PCA) for attack detection and classification based on abnormal traffic behavior. The design process consists of two phases. The first phase starts with intrusion detection. The detected abnormal traffic is passed to the second phase for attack-type classification. Both phases used three layers of RBM to detect and classify the attack. Each phase is separately analyzed on two benchmarked datasets: NSL-KDD has four attack types, and CSE-CIC-IDS2018, which is further treated with SMOTE for class balancing. The designed model has better prediction accuracy with 98.75% and 98.00% accuracy, and 0.01 and 0.03 false positive rates for the NSL-KDD and CSE-CIC-IDS2018 datasets, respectively. The attack type detection phase offers 98.00% accuracy for both datasets and 0.03 and 0.02 false positive rates for NSL-KDD and CSE-CIC-IDS2018, respectively. Results suggested that the proposed optimized DBN-based approach is robust and efficient for real-world applications.