返回
Development of Various Stacking Ensemble-Based HIDS Using ADFA Datasets
DOI:10.1109/OJCOMS.2025.3538101.png)
摘要
En 中文
The rapid increase in the number of cyber attacks and the emergence of various attack variations pose significant threats to the security of computer systems and networks. Various intrusion detection systems (IDS) are developed to defend computer systems and networks in response to these threats. One type of IDS, known as a host-based intrusion detection system (HIDS), focuses on securing a single host. Numerous HIDS have been proposed in the literature, incorporating various detection methods. This study develops multiple machine learning (ML) models and stacking ensemble based HIDS that can be used as detection methods in HIDS. Initially, n-grams, standard bag-of-words (BoW), binary BoW, probability BoW, and term frequency-inverse document frequency (TF-IDF) BoW methods are applied to the ADFA-LD and ADFA-WD datasets. Mutual information and k-means methods are used together for feature selection on the resulting BoW datasets. Individual models are created using either selected features or all features. Subsequently, the outputs of these individual models are used in extreme gradient boosting (XGBoost) and adaptive boosting (AdaBoost) models to develop stacking ensemble based models. The experimental results show that the best accuracy (ACC) among models using ADFA-LD based BoW datasets is achieved by the stacking ensemble based XGBoost model, which has an ACC of 0.9747. This XGBoost model utilizes the standard BoW dataset and selected features. Among models using ADFA-WD based BoW datasets, the stacking ensemble based XGBoost is also the most successful in terms of ACC, with an ACC of 0.9163, using the standard BoW dataset and all features.
Keyword:
Feature extraction
Long short term memory
Detectors
Stacking
Computer crime
Support vector machines
Computer security
Adaptation models
Standards
Intrusion detection
Intrusion detection system
host-based intrusion detection system
information security
machine learning
期刊
I
IF:
4.3
论文数:
1.7K
被引数:
991
机构
引用论文
A tfidfvectorizer and singular value decomposition based host intrusion detection system framework for detecting anomalous system processes
COMPUTERS & SECURITY
IF5.4
Host-based IDS: A review and open issues of an anomaly detection system in IoT基于主机的IDS: 物联网异常检测系统的回顾和开放问题
A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets用于评估边缘基于AI的安全系统的新分布式架构: Network TON_IoT数据集
An AI powered system call analysis with bag of word approaches for the detection of intrusions and malware in Australian Defence Force Academy and virtual machine monitor malware attack data set
EXPERT SYSTEMS
IF2.3

