Machine Learning Multi-Class Intrusion DetectionSystem Using Embedded Feature Selection and Multi-Level Hierarchy Classification
Pages
84-103Abstract
In recent years, network security has attracted significant research attention due to the growing frequency of attacks on computer networks. Among existing solutions, “Network Intrusion Detection Systems (NIDS)” play a central role. While binary NIDS effectively distinguish between normal and malicious traffic, they cannot accurately classify specific attack types. Multi-class intrusion detection systems address this limitation by enabling tailored responses for each attack category. This paper presents the development of a “multi-class Intrusion Detection System (IDS)” that integrates “Recursive Feature Addition (RFA)”, an embedded feature selection technique, with multi-level binary classifiers. The proposed system was evaluated using five machine learning algorithms: “Support Vector Machines (SVM)”, “Random Forests”, “J48”, “Random Tree”, and “J48Graft”. A hierarchical binary tree structure was employed to implement the multi-class detection, with performance assessed under two dataset distribution scenarios: “balanced” and “imbalanced”. To construct the overall “multi-class confusion matrix”, a novel estimation method that combines intermediate matrices from each binary sub-tree has been introduced.The ISCX 2012 intrusion detection benchmark dataset was used for evaluation, with results measured across five metrics: “Accuracy”, “F1-score”, “Detection Rate”, “False Alarm Rate (FAR)”, and “Precision”. Experimental findings show that “Random Tree” consistently achieved the best performance across both scenarios. For “balanced” datasets, it excelled in detecting DoS attacks, while for “imbalanced” datasets, it demonstrated superior efficiency in identifying Internal attacks. In addition, the proposed approach has demonstrated superiority over the baseline in terms of time required for (feature selection + classification hierarchy) and key metrics. These results highlight the effectiveness of the proposed multi-class IDS framework for enhancing intrusion detection in complex network environments
Keywords:
Identifiers
DOI: 10.33899/k610ap05
Download this PDF file
Statistics
How to Cite
Copyright and Licensing

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.








