• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

An Effective Anomaly Detection Approach based on Hybrid Unsupervised Learning Technologies in NIDS

Vol. 18, No. 2, February 29, 2024
10.3837/tiis.2024.02.012, Download Paper (Free):

Abstract

Internet users are exposed to sophisticated cyberattacks that intrusion detection systems have difficulty detecting. Therefore, research is increasing on intrusion detection methods that use artificial intelligence technology for detecting novel cyberattacks. Unsupervised learning-based methods are being researched that learn only from normal data and detect abnormal behaviors by finding patterns. This study developed an anomaly-detection method based on unsupervised machines and deep learning for a network intrusion detection system (NIDS). We present a hybrid anomaly detection approach based on unsupervised learning techniques using the autoencoder (AE), Isolation Forest (IF), and Local Outlier Factor (LOF) algorithms. An oversampling approach that increased the detection rate was also examined. A hybrid approach that combined deep learning algorithms and traditional machine learning algorithms was highly effective in setting the thresholds for anomalies without subjective human judgment. It achieved precision and recall rates respectively of 88.2% and 92.8% when combining two AEs, IF, and LOF while using an oversampling approach to learn more unknown normal data improved the detection accuracy. This approach achieved precision and recall rates respectively of 88.2% and 94.6%, further improving the detection accuracy compared with the hybrid method. Therefore, in NIDS the proposed approach provides high reliability for detecting cyberattacks.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
K. Kim, "An Effective Anomaly Detection Approach based on Hybrid Unsupervised Learning Technologies in NIDS," KSII Transactions on Internet and Information Systems, vol. 18, no. 2, pp. 494-510, 2024. DOI: 10.3837/tiis.2024.02.012.

[ACM Style]
Kangseok Kim. 2024. An Effective Anomaly Detection Approach based on Hybrid Unsupervised Learning Technologies in NIDS. KSII Transactions on Internet and Information Systems, 18, 2, (2024), 494-510. DOI: 10.3837/tiis.2024.02.012.

[BibTeX Style]
@article{tiis:90560, title="An Effective Anomaly Detection Approach based on Hybrid Unsupervised Learning Technologies in NIDS", author="Kangseok Kim and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2024.02.012}, volume={18}, number={2}, year="2024", month={February}, pages={494-510}}