A Stacking Ensemble with Heterogeneous Base Classifiers for DDoS and Multi-Class Network Attack Detection on the CICIDS2017 Dataset
DOI:
https://doi.org/10.54536/ajaset.v10i3.8373Keywords:
CICIDS2017 Dataset, Ddos, Heterogeneous Classifiers, Intrusion Detection, Stacking EnsembleAbstract
Volumetric and protocol floods are two most dangerous types of DDoS attacks, which affect network availability. The overall attack picture has become more complicated with advancement in technology, however, attacks can be of all shapes and sizes and many are lurking at the fringes of the everyday. One classifier will tend to overfit towards the majority class and the loss of this bias will cost a lot when the traffic comes from different families of attacks and the traffic is imbalanced. This problem can be address using stacking ensemble, Random Forest, an XGBoost model, k-Nearest Neighbours (kNN) and multilayer perceptron (MLP) classifiers. They are used as base classifiers to input into a logistic regression meta-learner; the design aims at both binary DDoS detection and finer multi-class classification. The model was carefully designed and tested using the CICIDS2017 dataset, and was developed by implementing and applying a systematic preprocessing pipeline that involves dealing with infinite and missing values, reducing correlated features, standardising input variables, and directly tackling class imbalance. The ensemble had an accuracy of 99.31%, macro-averaged F1 of 97.84% and 0.42% false positive based on the experimental simulation and outperform the existing base learners including a majority-voting baseline. Hence, the diversity of the base learners is more important than the number of base learners, and that stacking makes the diversity into a detector that is both accurate, and realistically deployable.
Downloads
References
Abdulganiyu, O. H., Tchakoucht, T., & Saheed, Y. K. (2023). A systematic literature review for network intrusion detection system (IDS). International Journal of Information Security, 22(5), 1125–1162. https://doi.org/10.1007/s10207-023-00682-2
Ahmad, R., Alsmadi, I., Alhamdani, W., & Tawalbeh, L. (2022). A comprehensive deep learning benchmark for IoT IDS. Computers & Security, 114, 102588. https://doi.org/10.1016/j.cose.2021.102588
Ahmim, A., Maglaras, L., Ferrag, M. A., Derdour, M., & Janicke, H. (2021). A novel hierarchical intrusion detection system based on decision tree and rules-based models. Journal of Network and Computer Applications, 178, 102983. https://doi.org/10.1016/j.jnca.2021.102983
Alani, M. M., & Awad, A. I. (2023). An intelligent two-layer intrusion detection system for the internet of things. IEEE Transactions on Industrial Informatics, 19(1), 683–692. https://doi.org/10.1109/TII.2022.3192035
Aljuhani, A. (2021). Machine learning approaches for combating distributed denial of service attacks in modern networking environments. IEEE Access, 9, 42236–42264. https://doi.org/10.1109/ACCESS.2021.3062909
Alotaibi, Y., & Ilyas, M. (2023). Ensemble-learning framework for intrusion detection to enhance internet of things devices security. Sensors, 23(12), 5568. https://doi.org/10.3390/s23125568
Alzahrani, A. O., & Alenazi, M. J. F. (2021). Designing a network intrusion detection system based on machine learning for software defined networks. Future Internet, 13(5), 111. https://doi.org/10.3390/fi13050111
Bhardwaj, A., Mangat, V., & Vig, R. (2021). Hyperband tuned deep neural network with well-posed stacked sparse autoencoder for detection of DDoS attacks in cloud. IEEE Access, 9, 87026–87047. https://doi.org/10.1109/ACCESS.2021.3088163
Bhati, B. S., Chugh, G., Al-Turjman, F., & Bhati, N. S. (2021). An improved ensemble based intrusion detection technique using XGBoost. Transactions on Emerging Telecommunications Technologies, 32(6), e4076. https://doi.org/10.1002/ett.4076
Disha, R. A., & Waheed, S. (2022). Performance analysis of machine learning models for intrusion detection systems using the Gini impurity-based weighted random forest algorithm. Cybersecurity, 5(1), 1. https://doi.org/10.1186/s42400-021-00103-8
Elsayed, M. S., Le-Khac, N. A., & Jurcut, A. D. (2021). InSDN: a novel SDN intrusion dataset. IEEE Access, 9, 42964–42980. https://doi.org/10.1109/ACCESS.2021.3066368
Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., & Janicke, H. (2022). Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access, 10, 40281–40306. https://doi.org/10.1109/ACCESS.2022.3165809
Gupta, N., Jindal, V., & Bedi, P. (2022). CSE-IDS: using cost-sensitive deep learning and ensemble algorithms to handle class imbalance in network-based intrusion detection systems. Computers & Security, 112, 102499. https://doi.org/10.1016/j.cose.2021.102499
Hnamte, V., & Hussain, J. (2023). DCNNBiLSTM: an efficient hybrid deep learning-based intrusion detection system. Telematics and Informatics Reports, 10, 100053. https://doi.org/10.1016/j.teler.2023.100053
Imrana, Y., Xiang, Y., Ali, L., & Abdul-Rauf, Z. (2021). A bidirectional LSTM deep learning approach for intrusion detection. Expert Systems with Applications, 185, 115524. https://doi.org/10.1016/j.eswa.2021.115524
Jiang, K., Wang, W., Wang, A., & Wu, H. (2021). Network intrusion detection combined hybrid sampling with deep hierarchical network. IEEE Access, 9, 32464–32476. https://doi.org/10.1109/ACCESS.2021.3060086
Kanna, P. R., & Santhi, P. (2021). Unified deep learning approach for efficient intrusion detection system using integrated spatial-temporal features. Knowledge-Based Systems, 226, 107132. https://doi.org/10.1016/j.knosys.2021.107132
Kasongo, S. M. (2023). A deep learning technique for intrusion detection system using a recurrent neural networks based framework. Computer Communications, 199, 113–125. https://doi.org/10.1016/j.comcom.2022.12.010
Khan, M. A. (2021). HCRNNIDS: hybrid convolutional recurrent neural network-based network intrusion detection system. Processes, 9(5), 834. https://doi.org/10.3390/pr9050834
Kilincer, I. F., Ertam, F., & Sengur, A. (2021). Machine learning methods for cyber security intrusion detection: Datasets and comparative study. Computer Networks, 188, 107840. https://doi.org/10.1016/j.comnet.2021.107840
Kumar, P., Gupta, G. P., & Tripathi, R. (2021). Toward design of an intelligent cyber attack detection system using hybrid feature reduced approach for IoT networks. Arabian Journal for Science and Engineering, 46(4), 3749–3778. https://doi.org/10.1007/s13369-020-05181-3
Lansky, J., Ali, S., Mohammadi, M., Majeed, M. K., Karim, S. H. T., Rashidi, S., Hosseinzadeh, M., & Rahmani, A. M. (2021). Deep learning-based intrusion detection systems: a systematic review. IEEE Access, 9,101574–101599. https://doi.org/10.1109/ACCESS.2021.3097247
Latif, S., Huma, Z. E., Jamal, S. S., Ahmed, F., Ahmad, J., Zahid, A., Dashtipour, K., Aftab, M. U., Ahmad, M., & Abbasi, Q. H. (2022). Intrusion detection framework for the internet of things using a dense random neural network. IEEE Transactions on Industrial Informatics, 18(9), 6435–6444. https://doi.org/10.1109/TII.2021.3130248
Le, T. T. H., Kim, H., Kang, H., & Kim, H. (2022). Classification and explanation for intrusion detection system based on ensemble trees and SHAP method. Sensors, 22(3), 1154. https://doi.org/10.3390/s22031154
Liu, Z., Thapa, N., Shaver, A., Roy, K., Yuan, X., & Khorsandroo, S. (2021). Anomaly detection on IoT network intrusion using machine learning. AI, 2(2), 230–243. https://doi.org/10.3390/ai2020014
Maseer, Z. K., Yusof, R., Bahaman, N., Mostafa, S. A., & Foozy, C. F. M. (2021). Benchmarking of machine learning for anomaly based intrusion detection systems in the CICIDS2017 dataset. IEEE Access, 9, 22351–22370. https://doi.org/10.1109/ACCESS.2021.3056614
Mhawi, D. N., Aldallal, A., & Hassan, S. (2022). Advanced feature-selection-based hybrid ensemble learning algorithms for network intrusion detection systems. Symmetry, 14(7), 1461. https://doi.org/10.3390/sym14071461
Moustafa, N., Koroniotis, N., Keshk, M., Zomaya, A. Y., & Tari, Z. (2023). Explainable intrusion detection for cyber defences in the internet of things: opportunities and solutions. IEEE Communications Surveys & Tutorials, 25(3), 1775–1807. https://doi.org/10.1109/COMST.2023.3280465
Nguyen, M. T., & Kim, K. (2023). Genetic convolutional neural network for intrusion detection systems. Future Generation Computer Systems, 113, 418–427. https://doi.org/10.1016/j.future.2020.07.042
Otoum, Y., Liu, D., & Nayak, A. (2022). DL-IDS: a deep learning-based intrusion detection framework for securing IoT. Transactions on Emerging Telecommunications Technologies, 33(3), e3803. https://doi.org/10.1002/ett.3803
Pelletier, Z., & Abualkibash, M. (2022). Evaluating the CIC IDS-2017 dataset using machine learning methods and creating multiple predictive models in the statistical computing language R. International Research Journal of Advanced Engineering and Science, 7(2), 187–192.
Rashid, M. M., Kamruzzaman, J., Hassan, M. M., Imam, T., & Gordon, S. (2022). Cyberattacks detection in IoT-based smart city applications using machine learning techniques. International Journal of Environmental Research and Public Health, 19(15), 9347. https://doi.org/10.3390/ijerph19159347
Rincy, N. T., & Gupta, R. (2021). Design and development of an efficient network intrusion detection system using ensemble machine learning techniques. Wireless Communications and Mobile Computing, 2021, 9974270. https://doi.org/10.1155/2021/9974270
Saheed, Y. K., Abiodun, A. I., Misra, S., Holone, M. K., & Colomo-Palacios, R. (2022). A machine learning-based intrusion detection for detecting internet of things network attacks. Alexandria Engineering Journal, 61(12), 9395–9409. https://doi.org/10.1016/j.aej.2022.02.063
Sarhan, M., Layeghy, S., & Portmann, M. (2022). Towards a standard feature set for network intrusion detection system datasets. Mobile Networks and Applications, 27(1), 357–370. https://doi.org/10.1007/s11036-021-01843-0
Seth, S., Singh, G., & Kaur Chahal, K. (2021). A novel time efficient learning-based approach for smart intrusion detection system. Journal of Big Data, 8(1), 111. https://doi.org/10.1186/s40537-021-00498-8
Sharma, N., & Yadav, N. S. (2023). Ensemble learning based classification of network intrusion detection on the CICIDS2017 dataset. Multimedia Tools and Applications, 82(20), 31023–31045. https://doi.org/10.1007/s11042-023-14749-8
Talukder, M. A., Hasan, K. F., Islam, M. M., Uddin, M. A., Akhter, A., Yousuf, M. A., Alharbi, F., & Moni, M. A. (2023). A dependable hybrid machine learning model for network intrusion detection. Journal of Information Security and Applications, 72, 103405. https://doi.org/10.1016/j.jisa.2022.103405
Thakkar, A., & Lohiya, R. (2021). A review on machine learning and deep learning perspectives of IDS for IoT: Recent updates, security issues, and challenges. Archives of Computational Methods in Engineering, 28(4), 3211–3243. https://doi.org/10.1007/s11831-020-09496-0
Thakkar, A., & Lohiya, R. (2023). A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artificial Intelligence Review, 55(1), 453–563. https://doi.org/10.1007/s10462-021-10037-9
Ullah, I., & Mahmoud, Q. H. (2021). Design and development of a deep learning-based model for anomaly detection in IoT networks. IEEE Access, 9,103906–103926.https://doi.org/10.1109/ACCESS.2021.3094024
Vinayakumar, R., Alazab, M., Srinivasan, S., Pham, Q. V., Padannayil, S. K., & Simran, K. (2021). A visualized botnet detection system based on deep learning for the internet of things networks of smart cities. IEEE Transactions on Industry Applications, 56(4), 4436–4456. https://doi.org/10.1109/TIA.2020.2971952
Wang, Z., Liu, Y., He, D., & Chan, S. (2021). Intrusion detection methods based on integrated deep learning model. Computers & Security, 103, 102177. https://doi.org/10.1016/j.cose.2021.102177
Yang, L., & Shami, A. (2022). A lightweight concept drift detection and adaptation framework for IoT data streams. IEEE Internet of Things Magazine, 4(2), 96–101. https://doi.org/10.1109/IOTM.0001.2100012
Zhou, Y., Cheng, G., Jiang, S., & Dai, M. (2021). Building an efficient intrusion detection system based on feature selection and ensemble classifier. Computer Networks, 174, 107247. https://doi.org/10.1016/j.comnet.2020.107247



