Supervised Feature Selection Techniques in Network Intrusion Detection: a Critical Review
Machine Learning (ML) techniques are becoming an invaluable support for network intrusion detection, especially in revealing anomalous flows, which often hide cyber-threats. Typically, ML algorithms are exploited to classify/recognize data traffic on the basis of statistical features such as inter-arrival times, packets length distribution, mean number of flows, etc. Dealing with the vast diversity and number of features that typically characterize data traffic is a hard problem. This results in the following issues: i) the presence of so many features leads to lengthy training processes (particularly when features are highly correlated), while prediction accuracy does not proportionally improve; ii) some of the features may introduce bias during the classification process, particularly those that have scarce relation with the data traffic to be classified. To this end, by reducing the feature space and retaining only the most significant features, Feature Selection (FS) becomes a crucial pre-processing step in network management and, specifically, for the purposes of network intrusion detection. In this review paper, we complement other surveys in multiple ways: i) evaluating more recent datasets (updated w.r.t. obsolete KDD 99) by means of a designed-from-scratch Python-based procedure; ii) providing a synopsis of most credited FS approaches in the field of intrusion detection, including Multi-Objective Evolutionary techniques; iii) assessing various experimental analyses such as feature correlation, time complexity, and performance. Our comparisons offer useful guidelines to network/security managers who are considering the incorporation of ML concepts into network intrusion detection, where trade-offs between performance and resource consumption are crucial.
Code (0)
등록된 구현이 없습니다.
Tasks
Feature Correlationfeature selectionIntrusion DetectionManagementNetwork Intrusion DetectionMethods 이 논문이 사용한 방법론
Similar Papers 제목 키워드 기반
Building an Efficient Intrusion Detection System Based on Feature Selection and Ensemble Classifier
Intrusion detection system (IDS) is one of extensively used techniques in a network topology to safeguard the integrity and availability of sensitive assets in the protected systems. Although many supervised and unsuperv…
Anomaly DetectionDimensionality ReductionEnsemble Learningfeature selection+3Detection-Rate-Emphasized Multi-objective Evolutionary Feature Selection for Network Intrusion Detection
Network intrusion detection is one of the most important issues in the field of cyber security, and various machine learning techniques have been applied to build intrusion detection systems. However, since the number of…
Evolutionary Algorithmsfeature selectionIntrusion DetectionNetwork Intrusion DetectionShallow and Deep Networks Intrusion Detection System: A Taxonomy and Survey
Intrusion detection has attracted a considerable interest from researchers and industries. The community, after many years of research, still faces the problem of building reliable and efficient IDS that are capable of h…
BIG-bench Machine Learningfeature selectionIntrusion DetectionSurveyMachine Learning-Based Intrusion Detection: Feature Selection versus Feature Extraction
Internet of things (IoT) has been playing an important role in many sectors, such as smart cities, smart agriculture, smart healthcare, and smart manufacturing. However, IoT devices are highly vulnerable to cyber-attacks…
feature selectionIntrusion DetectionNetwork Intrusion DetectionXAI-based Feature Selection for Improved Network Intrusion Detection Systems
Explainability and evaluation of AI models are crucial parts of the security of modern intrusion detection systems (IDS) in the network security field, yet they are lacking. Accordingly, feature selection is essential fo…
AttributeDecision Makingfeature selectionIntrusion Detection+1