A Stacking Ensemble with Heterogeneous Base Classifiers for DDoS and Multi-Class Network Attack Detection on the CICIDS2017 Dataset

Authors

  • Segun Omotayo Olorunyomi Department of Computer Science, Afe Babalola University, Ado - Ekiti, Nigeria
  • Joshephine Olamatanmi Mebawondu Department of Computer Science, Afe Babalola University, Ado - Ekiti, Nigeria
  • Oluwatoyin Bunmi Abiola Department of Computer Science, Afe Babalola University, Ado - Ekiti, Nigeria
  • Saidat Adebukola Onashoga Department of Cybersecurity and Data Science,Federal University of Agriculture Abeokuta, Nigeria
  • Ayodeji Ireti Fasiku Department of Computer Engineering, Ekiti State University, Ado - Ekiti, Nigeria https://orcid.org/0000-0002-2864-9472
  • Adeyemi Folasade Department of Computer Science, Federal University of Technology, Akure, Ondo State, Nigeria

DOI:

https://doi.org/10.54536/ajaset.v10i3.8373

Keywords:

CICIDS2017 Dataset, Ddos, Heterogeneous Classifiers, Intrusion Detection, Stacking Ensemble

Abstract

Volumetric and protocol floods are two most dangerous types of DDoS attacks, which affect network availability. The overall attack picture has become more complicated with advancement in technology, however, attacks can be of all shapes and sizes and many are lurking at the fringes of the everyday. One classifier will tend to overfit towards the majority class and the loss of this bias will cost a lot when the traffic comes from different families of attacks and the traffic is imbalanced. This problem can be address using stacking ensemble, Random Forest, an XGBoost model, k-Nearest Neighbours (kNN) and multilayer perceptron (MLP) classifiers. They are used as base classifiers to input into a logistic regression meta-learner; the design aims at both binary DDoS detection and finer multi-class classification. The model was carefully designed and tested using the CICIDS2017 dataset, and was developed by implementing and applying a systematic preprocessing pipeline that involves dealing with infinite and missing values, reducing correlated features, standardising input variables, and directly tackling class imbalance. The ensemble had an accuracy of 99.31%, macro-averaged F1 of 97.84% and 0.42% false positive based on the experimental simulation and outperform the existing base learners including a majority-voting baseline. Hence, the diversity of the base learners is more important than the number of base learners, and that stacking makes the diversity into a detector that is both accurate, and realistically deployable.

Downloads

Download data is not yet available.

References

Abdulganiyu, O. H., Tchakoucht, T., & Saheed, Y. K. (2023). A systematic literature review for network intrusion detection system (IDS). International Journal of Information Security, 22(5), 1125–1162. https://doi.org/10.1007/s10207-023-00682-2

Ahmad, R., Alsmadi, I., Alhamdani, W., & Tawalbeh, L. (2022). A comprehensive deep learning benchmark for IoT IDS. Computers & Security, 114, 102588. https://doi.org/10.1016/j.cose.2021.102588

Ahmim, A., Maglaras, L., Ferrag, M. A., Derdour, M., & Janicke, H. (2021). A novel hierarchical intrusion detection system based on decision tree and rules-based models. Journal of Network and Computer Applications, 178, 102983. https://doi.org/10.1016/j.jnca.2021.102983

Alani, M. M., & Awad, A. I. (2023). An intelligent two-layer intrusion detection system for the internet of things. IEEE Transactions on Industrial Informatics, 19(1), 683–692. https://doi.org/10.1109/TII.2022.3192035

Aljuhani, A. (2021). Machine learning approaches for combating distributed denial of service attacks in modern networking environments. IEEE Access, 9, 42236–42264. https://doi.org/10.1109/ACCESS.2021.3062909

Alotaibi, Y., & Ilyas, M. (2023). Ensemble-learning framework for intrusion detection to enhance internet of things devices security. Sensors, 23(12), 5568. https://doi.org/10.3390/s23125568

Alzahrani, A. O., & Alenazi, M. J. F. (2021). Designing a network intrusion detection system based on machine learning for software defined networks. Future Internet, 13(5), 111. https://doi.org/10.3390/fi13050111

Bhardwaj, A., Mangat, V., & Vig, R. (2021). Hyperband tuned deep neural network with well-posed stacked sparse autoencoder for detection of DDoS attacks in cloud. IEEE Access, 9, 87026–87047. https://doi.org/10.1109/ACCESS.2021.3088163

Bhati, B. S., Chugh, G., Al-Turjman, F., & Bhati, N. S. (2021). An improved ensemble based intrusion detection technique using XGBoost. Transactions on Emerging Telecommunications Technologies, 32(6), e4076. https://doi.org/10.1002/ett.4076

Disha, R. A., & Waheed, S. (2022). Performance analysis of machine learning models for intrusion detection systems using the Gini impurity-based weighted random forest algorithm. Cybersecurity, 5(1), 1. https://doi.org/10.1186/s42400-021-00103-8

Elsayed, M. S., Le-Khac, N. A., & Jurcut, A. D. (2021). InSDN: a novel SDN intrusion dataset. IEEE Access, 9, 42964–42980. https://doi.org/10.1109/ACCESS.2021.3066368

Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., & Janicke, H. (2022). Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access, 10, 40281–40306. https://doi.org/10.1109/ACCESS.2022.3165809

Gupta, N., Jindal, V., & Bedi, P. (2022). CSE-IDS: using cost-sensitive deep learning and ensemble algorithms to handle class imbalance in network-based intrusion detection systems. Computers & Security, 112, 102499. https://doi.org/10.1016/j.cose.2021.102499

Hnamte, V., & Hussain, J. (2023). DCNNBiLSTM: an efficient hybrid deep learning-based intrusion detection system. Telematics and Informatics Reports, 10, 100053. https://doi.org/10.1016/j.teler.2023.100053

Imrana, Y., Xiang, Y., Ali, L., & Abdul-Rauf, Z. (2021). A bidirectional LSTM deep learning approach for intrusion detection. Expert Systems with Applications, 185, 115524. https://doi.org/10.1016/j.eswa.2021.115524

Jiang, K., Wang, W., Wang, A., & Wu, H. (2021). Network intrusion detection combined hybrid sampling with deep hierarchical network. IEEE Access, 9, 32464–32476. https://doi.org/10.1109/ACCESS.2021.3060086

Kanna, P. R., & Santhi, P. (2021). Unified deep learning approach for efficient intrusion detection system using integrated spatial-temporal features. Knowledge-Based Systems, 226, 107132. https://doi.org/10.1016/j.knosys.2021.107132

Kasongo, S. M. (2023). A deep learning technique for intrusion detection system using a recurrent neural networks based framework. Computer Communications, 199, 113–125. https://doi.org/10.1016/j.comcom.2022.12.010

Khan, M. A. (2021). HCRNNIDS: hybrid convolutional recurrent neural network-based network intrusion detection system. Processes, 9(5), 834. https://doi.org/10.3390/pr9050834

Kilincer, I. F., Ertam, F., & Sengur, A. (2021). Machine learning methods for cyber security intrusion detection: Datasets and comparative study. Computer Networks, 188, 107840. https://doi.org/10.1016/j.comnet.2021.107840

Kumar, P., Gupta, G. P., & Tripathi, R. (2021). Toward design of an intelligent cyber attack detection system using hybrid feature reduced approach for IoT networks. Arabian Journal for Science and Engineering, 46(4), 3749–3778. https://doi.org/10.1007/s13369-020-05181-3

Lansky, J., Ali, S., Mohammadi, M., Majeed, M. K., Karim, S. H. T., Rashidi, S., Hosseinzadeh, M., & Rahmani, A. M. (2021). Deep learning-based intrusion detection systems: a systematic review. IEEE Access, 9,101574–101599. https://doi.org/10.1109/ACCESS.2021.3097247

Latif, S., Huma, Z. E., Jamal, S. S., Ahmed, F., Ahmad, J., Zahid, A., Dashtipour, K., Aftab, M. U., Ahmad, M., & Abbasi, Q. H. (2022). Intrusion detection framework for the internet of things using a dense random neural network. IEEE Transactions on Industrial Informatics, 18(9), 6435–6444. https://doi.org/10.1109/TII.2021.3130248

Le, T. T. H., Kim, H., Kang, H., & Kim, H. (2022). Classification and explanation for intrusion detection system based on ensemble trees and SHAP method. Sensors, 22(3), 1154. https://doi.org/10.3390/s22031154

Liu, Z., Thapa, N., Shaver, A., Roy, K., Yuan, X., & Khorsandroo, S. (2021). Anomaly detection on IoT network intrusion using machine learning. AI, 2(2), 230–243. https://doi.org/10.3390/ai2020014

Maseer, Z. K., Yusof, R., Bahaman, N., Mostafa, S. A., & Foozy, C. F. M. (2021). Benchmarking of machine learning for anomaly based intrusion detection systems in the CICIDS2017 dataset. IEEE Access, 9, 22351–22370. https://doi.org/10.1109/ACCESS.2021.3056614

Mhawi, D. N., Aldallal, A., & Hassan, S. (2022). Advanced feature-selection-based hybrid ensemble learning algorithms for network intrusion detection systems. Symmetry, 14(7), 1461. https://doi.org/10.3390/sym14071461

Moustafa, N., Koroniotis, N., Keshk, M., Zomaya, A. Y., & Tari, Z. (2023). Explainable intrusion detection for cyber defences in the internet of things: opportunities and solutions. IEEE Communications Surveys & Tutorials, 25(3), 1775–1807. https://doi.org/10.1109/COMST.2023.3280465

Nguyen, M. T., & Kim, K. (2023). Genetic convolutional neural network for intrusion detection systems. Future Generation Computer Systems, 113, 418–427. https://doi.org/10.1016/j.future.2020.07.042

Otoum, Y., Liu, D., & Nayak, A. (2022). DL-IDS: a deep learning-based intrusion detection framework for securing IoT. Transactions on Emerging Telecommunications Technologies, 33(3), e3803. https://doi.org/10.1002/ett.3803

Pelletier, Z., & Abualkibash, M. (2022). Evaluating the CIC IDS-2017 dataset using machine learning methods and creating multiple predictive models in the statistical computing language R. International Research Journal of Advanced Engineering and Science, 7(2), 187–192.

Rashid, M. M., Kamruzzaman, J., Hassan, M. M., Imam, T., & Gordon, S. (2022). Cyberattacks detection in IoT-based smart city applications using machine learning techniques. International Journal of Environmental Research and Public Health, 19(15), 9347. https://doi.org/10.3390/ijerph19159347

Rincy, N. T., & Gupta, R. (2021). Design and development of an efficient network intrusion detection system using ensemble machine learning techniques. Wireless Communications and Mobile Computing, 2021, 9974270. https://doi.org/10.1155/2021/9974270

Saheed, Y. K., Abiodun, A. I., Misra, S., Holone, M. K., & Colomo-Palacios, R. (2022). A machine learning-based intrusion detection for detecting internet of things network attacks. Alexandria Engineering Journal, 61(12), 9395–9409. https://doi.org/10.1016/j.aej.2022.02.063

Sarhan, M., Layeghy, S., & Portmann, M. (2022). Towards a standard feature set for network intrusion detection system datasets. Mobile Networks and Applications, 27(1), 357–370. https://doi.org/10.1007/s11036-021-01843-0

Seth, S., Singh, G., & Kaur Chahal, K. (2021). A novel time efficient learning-based approach for smart intrusion detection system. Journal of Big Data, 8(1), 111. https://doi.org/10.1186/s40537-021-00498-8

Sharma, N., & Yadav, N. S. (2023). Ensemble learning based classification of network intrusion detection on the CICIDS2017 dataset. Multimedia Tools and Applications, 82(20), 31023–31045. https://doi.org/10.1007/s11042-023-14749-8

Talukder, M. A., Hasan, K. F., Islam, M. M., Uddin, M. A., Akhter, A., Yousuf, M. A., Alharbi, F., & Moni, M. A. (2023). A dependable hybrid machine learning model for network intrusion detection. Journal of Information Security and Applications, 72, 103405. https://doi.org/10.1016/j.jisa.2022.103405

Thakkar, A., & Lohiya, R. (2021). A review on machine learning and deep learning perspectives of IDS for IoT: Recent updates, security issues, and challenges. Archives of Computational Methods in Engineering, 28(4), 3211–3243. https://doi.org/10.1007/s11831-020-09496-0

Thakkar, A., & Lohiya, R. (2023). A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artificial Intelligence Review, 55(1), 453–563. https://doi.org/10.1007/s10462-021-10037-9

Ullah, I., & Mahmoud, Q. H. (2021). Design and development of a deep learning-based model for anomaly detection in IoT networks. IEEE Access, 9,103906–103926.https://doi.org/10.1109/ACCESS.2021.3094024

Vinayakumar, R., Alazab, M., Srinivasan, S., Pham, Q. V., Padannayil, S. K., & Simran, K. (2021). A visualized botnet detection system based on deep learning for the internet of things networks of smart cities. IEEE Transactions on Industry Applications, 56(4), 4436–4456. https://doi.org/10.1109/TIA.2020.2971952

Wang, Z., Liu, Y., He, D., & Chan, S. (2021). Intrusion detection methods based on integrated deep learning model. Computers & Security, 103, 102177. https://doi.org/10.1016/j.cose.2021.102177

Yang, L., & Shami, A. (2022). A lightweight concept drift detection and adaptation framework for IoT data streams. IEEE Internet of Things Magazine, 4(2), 96–101. https://doi.org/10.1109/IOTM.0001.2100012

Zhou, Y., Cheng, G., Jiang, S., & Dai, M. (2021). Building an efficient intrusion detection system based on feature selection and ensemble classifier. Computer Networks, 174, 107247. https://doi.org/10.1016/j.comnet.2020.107247

Downloads

Published

2026-09-29

How to Cite

Olorunyomi, S. O. ., Mebawondu, J. O. ., Abiola, O. B. ., Onashoga, S. A. ., Fasiku, A. I. ., & Folasade, A. . (2026). A Stacking Ensemble with Heterogeneous Base Classifiers for DDoS and Multi-Class Network Attack Detection on the CICIDS2017 Dataset. American Journal of Agricultural Science, Engineering, and Technology, 10(3), 1-10. https://doi.org/10.54536/ajaset.v10i3.8373

Similar Articles

You may also start an advanced similarity search for this article.