Stacked Ensemble Learning for Effective Flow-Based Intrusion Detection System
Stacked Ensemble Learning for Effective Flow-Based Intrusion Detection System
Pages
64-71Abstract
As developing cyber threats complexity and sophistication, traditional Network Intrusion Detection Systems (NIDS) face difficulties in detecting attacks within an acceptable time. For these challenges, this paper presents a new flow-based NIDS framework utilizing the benefits of Advanced Machine Learning methods, specifically the heterogeneous stacking ensemble. That leads to enhancing the detection performance in different attack scenarios. The proposed system merges three different base learner algorithms: Naïve Bayes (NB), Random Forest (RF), and eXtreme Gradient Boosting (XGBoost) with two different stackers(meta-learners): J48 decision tree and Logistic Regression (LR). The proposed system uses the comprehensive benchmark CSE-CIC-IDS-2018 dataset for testing and evaluation. In order to reduce the dimension of the feature space and to improve the model efficiency, feature selection is used with the aid of Mutual Information (MI). The experimental results showed that the LR-based meta-learner outperforms J48, achieving superior results of 97.98%, 98.90%, 93.92%, and 96.34% for accuracy, precision, recall, and f1-score, respectively. These results represent significant enhancements over the individual base classifiers and traditional ensemble methods. This can be used to build modern, effective cybersecurity applications that combine diverse machine learning algorithms with strategic feature engineering.
Keywords:
Identifiers
Download this PDF file
Statistics
How to Cite
Copyright and Licensing

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.








