TY - GEN
T1 - Optimizing Intrusion Detection
T2 - 2024 International Conference on Information Technology Research and Innovation, ICITRI 2024
AU - Priambodo, Anas Rachmadi
AU - Valasev, Riza Sauqi
AU - Phedra, William
AU - Faisal, Muhammad Najmi
AU - Pratomo, Baskoro Adi
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - Advanced Network Intrusion Detection Systems (NIDS) are needed because cybersecurity threats evolve. Managing dataset class imbalance and rapidly recognizing and categorizing network and host-level threats are priority issues. To solve this, we used Convolutional Neural Networks (CNNs), Gated Recurrent Units (GRUs), class balance, and Principal Component Analysis (PCA) in a hybrid deep learning strategy. Using the CIC-IDS2018 dataset, we trained our models and evaluated their performance based on precision, recall, False Positive Rate (FPR), True Positive Rate (TPR), and other metrics. We tested the CNN-GRU model in three data processing scenarios: without balancing, with undersampling, and with PCA. The balanced models, particularly with PCA, improved computing efficiency, although the unbalanced model achieved the highest accuracy. Specifically, combining CNN and GRU without balancing (Method 1) resulted in an accuracy of 99.99%, making it the most computationally intensive. This approach was the most computationally intensive. Method 2, which combined CNN and GRU with undersampling, achieved a slightly lower accuracy of 99.98% but significantly reduced training time. Though slightly less accurate at 99.98%, it considerably reduces training time. The most computationally efficient method was Method 3, which incorporated CNN-GRU with PCA and undersampling, resulting in an accuracy of 98.88%. In McNemar's tests, Methods 1 and 2 performed similarly, whereas Methods 1 and 3 did not. The study found that application requirements affect model choice, including accuracy-efficiency trade-offs. By balancing precision and processing resources, hybrid deep learning may improve NIDS.
AB - Advanced Network Intrusion Detection Systems (NIDS) are needed because cybersecurity threats evolve. Managing dataset class imbalance and rapidly recognizing and categorizing network and host-level threats are priority issues. To solve this, we used Convolutional Neural Networks (CNNs), Gated Recurrent Units (GRUs), class balance, and Principal Component Analysis (PCA) in a hybrid deep learning strategy. Using the CIC-IDS2018 dataset, we trained our models and evaluated their performance based on precision, recall, False Positive Rate (FPR), True Positive Rate (TPR), and other metrics. We tested the CNN-GRU model in three data processing scenarios: without balancing, with undersampling, and with PCA. The balanced models, particularly with PCA, improved computing efficiency, although the unbalanced model achieved the highest accuracy. Specifically, combining CNN and GRU without balancing (Method 1) resulted in an accuracy of 99.99%, making it the most computationally intensive. This approach was the most computationally intensive. Method 2, which combined CNN and GRU with undersampling, achieved a slightly lower accuracy of 99.98% but significantly reduced training time. Though slightly less accurate at 99.98%, it considerably reduces training time. The most computationally efficient method was Method 3, which incorporated CNN-GRU with PCA and undersampling, resulting in an accuracy of 98.88%. In McNemar's tests, Methods 1 and 2 performed similarly, whereas Methods 1 and 3 did not. The study found that application requirements affect model choice, including accuracy-efficiency trade-offs. By balancing precision and processing resources, hybrid deep learning may improve NIDS.
KW - Class Balancing
KW - Convolutional Neural Networks
KW - Gated Recurrent Units
KW - Network Intrusion Detection
KW - Principal Component Analysis
UR - https://www.scopus.com/pages/publications/85207103367
U2 - 10.1109/ICITRI62858.2024.10698997
DO - 10.1109/ICITRI62858.2024.10698997
M3 - Conference contribution
AN - SCOPUS:85207103367
T3 - Proceeding - 2024 International Conference on Information Technology Research and Innovation, ICITRI 2024
SP - 7
EP - 12
BT - Proceeding - 2024 International Conference on Information Technology Research and Innovation, ICITRI 2024
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 5 September 2024 through 6 September 2024
ER -