A Novel Approach of Enhancing and Developing IDS to Use Ml for Analyzing Malicious Attacks
摘要
This paper offers a new method for improving network security by using machine learning (ML) methods for the design and execution of an intrusion detection system (IDS). The principal objective is to tackle present obstacles in real-time identification of threats by the smooth integration of machine learning models, such as XGBoost, Random Forest, SVM, and Logistic Regression, with the Suricata intrusion detection system. An ELK-based visualization dashboard is also included in the system that is suggested to help with effective tracking and security incident response. The study addresses shortcomings in current systems, including the challenges associated with real-time threat detection, the intricacy of ML integration, and the requirement for enhanced reporting and visualization. Incoming requests are categorized by the working model as either normal or incursions, with the latter being further divided into DDoS, R2L, U2R, and probing attacks. This study improves on effective activation functions, improved feature selection, and empirical assessments of ML models for adaptable network intrusion detection by utilizing information gathered from four referenced studies. The accuracy of the results is promising, and the K-Neighbors Classifier proves to be a dependable option for further study and application.