Clustering Enabled Classification using Ensemble Feature Selection for Intrusion Detection

  • Fadi Salo
  • , Mohammad Noor Injadat
  • , Abdallah Moubayed
  • , Ali Bou Nassif
  • , Aleksander Essex

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

44 Scopus citations

Abstract

Machine learning has been leveraged to increase the effectiveness of intrusion detection systems (IDSs). The focus of this approach, however, has largely be on detecting known attack patterns based on outdated datasets. In this paper, we propose an ensemble feature selection method along with an anomaly detection method that combines unsupervised and supervised machine learning techniques to classify network traffic to identify previously unseen attack patterns. To that end, three different feature selection techniques are used as part of an ensemble model that selects 8 common features. Moreover, k-Means clustering is used to first partition the training instances into k clusters using the Manhattan distance. A classification model is then built based on the resulting clusters, which represent a density region of normal or anomaly instances. This in turn helps determine the effectiveness of the clustering in detecting unknown attack patterns within the data. The performance of our classifier is evaluated using the Kyoto dataset, which was collected between 2006 and 2015. To our knowledge, no previous work proposed such a framework that combines unsupervised and supervised machine learning approaches using this dataset. Experimental results show the effectiveness of the proposed framework in detecting previously unseen attack patterns compared to the traditional classification approach.

Original languageEnglish
Title of host publication2019 International Conference on Computing, Networking and Communications, ICNC 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages276-281
Number of pages6
ISBN (Electronic)9781538692233
DOIs
StatePublished - 8 Apr 2019
Externally publishedYes
Event2019 International Conference on Computing, Networking and Communications, ICNC 2019 - Honolulu, United States
Duration: 18 Feb 201921 Feb 2019

Publication series

Name2019 International Conference on Computing, Networking and Communications, ICNC 2019

Conference

Conference2019 International Conference on Computing, Networking and Communications, ICNC 2019
Country/TerritoryUnited States
CityHonolulu
Period18/02/1921/02/19

Bibliographical note

Publisher Copyright:
© 2019 IEEE.

Keywords

  • Classification
  • Ensemble feature selection
  • Kyoto dataset
  • Network anomaly detection
  • k-means clustering

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Software
  • Hardware and Architecture

Fingerprint

Dive into the research topics of 'Clustering Enabled Classification using Ensemble Feature Selection for Intrusion Detection'. Together they form a unique fingerprint.

Cite this