VFAST Transactions on Software Engineering
[Link]
VFAST Transactions on Software Engineering Volume 2024, ISSN(e):
12, Issue2309-3978,
2, 2024 ISSN(p): 2411-6246
Volume 12, Number 2, April-June 2024 pp: 95- 113
Intrusion Detection Using Machine Learning
and Deep Learning Models on Cyber Security
Attacks
1 , Junaid Khan 1 , Shah Hussain Bangash
Irfanullah Khan 1 , Waqas Ahmad 1* ,
Muhammad Asad Iftikhar 2 , Khalid Hameed 2
1
Department of Computer Science Iqra National University Peshawar,Pakistan; 2 CECOS
University of IT and Emerging Sciences
Keywords: Machine Abstract
Learning Algorithms, To detect and stop harmful activity in computer networks, network intrusion detection
Deep Learning
is an essential part of cybersecurity defensive systems. It is becoming more difficult for
Algorithms, Network
Intrusion Detection, traditional rule-based techniques to identify new attack vectors in the face of the increas-
Cyber Security Attacks, ing complexity and diversity of cyber threats. Machine learning (ML) and deep learning
Countermeasures Cyber (DL) models can analyze vast amounts of network traffic data and automatically identify
Attacks.
patterns and anomalies, there has been a surge in interest in using these models for
Journal Info: network intrusion detection. This paper examines the approaches, algorithms, and real-
Submitted: world applications of machine learning and deep learning techniques for network intru-
April 20, 2024
sion detection in order to present a thorough review of the state-of-the-art in countering
Accepted:
May 25, 2024
cyber threats. We assess ML and DL-based intrusion detection systems’ effectiveness,
Published: strengths, and weaknesses in a range of attack scenarios and network environments by
June 24, 2024 synthesizing current literature and empirical research. Additionally, we talk about new
developments, obstacles, and paths forward in the areas of transfer learning, adversar-
ial robustness, and ensemble learning. The understanding gained from this investigation
clarifies the potential of ML and DL models in strengthening defenses against changing
cyber threats, reducing risks, and protecting vital assets. In deep learning autoencode
accuracy 68% less than other models. The performance of the CNN and LSTM algorithm
is impressive and outperformed with 100% accuracy on cyber security attacks datasets.
Machine learning algorithm accuracy rate of SVM and KNN 100% while logistic regression
accuracy is 99% GNB accuracy 80% with training data of the models. The overall models
perforamance deep learning increadible accuracy with 100% on the training and testing
data.
*Correspondence author email address: [Link]@[Link],onlinesoftteach@gmail.
com
DOI: 10.21015/vtse.v12i2.1817
This work is licensed under a Creative Commons Attribution 3.0 License.
95
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
1 Introduction with greater accuracy and robust behavior [7]. The
Network attacks pose cybersecurity risks, necessitat- compares deep discriminative intrusion detection
ing intrusion detection systems. Advanced methods methods using deep learning strategies, using new
like machine learning and deep learning are being datasets and performance indicators like false alarm
explored to address the limitations of traditional rate, accuracy, and detection rate [8]. In the digital
rule-based approaches in handling dynamic cyber age, the internet is crucial for communication and
threats [1]. system engineering, making security sensitive due
Machine learning and deep learning models im- to sensitive data. Network detection aids in system
prove intrusion detection by learning patterns from security screening, while intrusion detection aims to
network traffic data, detecting sophisticated attack launch attacks. Advancements in intrusion detection
vectors and constantly adapting to new threats, mak- (ID) have made it the second line of defense after fire-
ing them valuable cybersecurity tools [2]. This study walls . Network intrusion detection systems monitor
reviews network intrusion detection using machine network traffic to identify suspicious activity.
learning and deep learning models, discussing their They are widely used for system security, with
merits, limitations, and practical consequences, dis- two types: crowd-based and net-based. Host-based
cussing practical difficulties, and offering solutions systems use system histories and information to filter
[3]. equipment and record archives. Intrusion detection
However, the machine and deep learning technolo- investigators have considered machine learning tech-
gies critically examine the effectiveness of ML and niques for database searching, suggesting supervised
DL-based NIDS in various attack scenarios and net- and unsupervised learning. Despite numerous stud-
work topologies, discussing new trends for enhanced ies, challenges persist in identifying disruptions in
intrusion detection systems [4]. The significance of system arrival circulation, leading to uneven detection
machine learning and deep learning in enhancing rates and high false positives. The data set includes
network security defences against cyber threats, training data and jobless input attributes [9].
thereby enhancing resilience, reducing risks, and pro-
tecting vital assets [5]. The latest technologies explore
2 STATE-OF-THE-ART
Parasuraman Kumar [Link], proposed study examines
deep learning techniques for cyber security intrusion
the use of DEEP learning neural networks for intrusion
detection, analyzing popular datasets and examining
detection in cyberattacks. As the internet becomes
seven deep learning models: deep autoencoders,
a crucial communication tool, security becomes a
constrained Boltzmann machines, convolutional
sensitive issue due to sensitive data. Network detec-
neural networks, deep belief networks, deep neu-
tion aids in system security screening, with intrusion
ral networks, and internet-connected device-based.
detection becoming the second line of defense behind
Additionally, cyberattacks are increasingly targeting
firewalls [10]. Zeeshan Ahmad [Link], studied explores
Critical National Infrastructures (CNIs), primarily re-
deep learning and machine learning techniques for
lying on Industrial Control Systems (ICS). Protection
network intrusion detection systems. With the rapid
of ICSs and CNIs is crucial at national, international,
growth of networks and data, new attacks and hack-
and organizational levels. Europe has implemented
ers pose challenges to network security. Intrusion
laws to secure networks, information, and electronic
detection systems (IDS) protect networks by analyzing
communications [6]. Intrusion detection systems
traffic, but researchers struggle to improve detection
(IDS) are a crucial second line of protection against
accuracy and reduce false alarm rates [11]. Niraj
cyberattacks, used in conjunction with access control,
Thapa [Link], worked on intrusion detection system
authentication, and encryption techniques. They
(IDS) utilizing deep learning and machine learning
differentiate between malicious and benign activity
models, aiming to improve cybersecurity by achiev-
using rules. Data mining aids in implementing IDSs
96
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
ing low false alarm rates and high detection rates utilizing DBN-Softmax, a deep neural network used in
. Bambang Susilo [Link], researched on deep Learn- natural language processing and image identification
ing Algorithm for Intrusion Detection in Internet of [16].
Things Networks addresses security challenges in IoT
devices. While existing techniques have addressed 2.0.1 Intrusion Detection System (IDS)
these issues, there’s still room for improvement, and Challenges in Cyber Security
machine learning is a suggested strategy to enhance Challenge 1 Scalability: Due to scalability concerns,
IoT security [12]. Hamed Alqahtani [Link], focused deploying IDS across large and complex networks can
on increasing complexity of cyber-security due to be difficult. Careful design and resource allocation
increased computer connectivity and applications are necessary to provide consistent coverage and
necessitates robust defense against cyberattacks. detection efficacy across all network segments and
Machine learning classification techniques have been devices[17].
used to create data-driven intrusion detection sys- Challenge 2 Adaptability to Changing Threats:
tems, potentially contributing to cybersecurity [13]. As a result of the ongoing evolution of cyber threats,
Devrim Akgun et. A deep learning-based cybersecurity intrusion detection systems must update and modify
intrusion detection model for DDoS attacks has been their detection techniques. This necessitates quick
developed, utilizing machine learning techniques. The updates to IDS rules and signatures as well as ongoing
model uses models from LSTM, CNN, and DNN, and monitoring of newly developing threats[18].
is tested on the widely used CIC-DDoS2019 dataset. Challenge 3: Network environments are complex
Preprocessing methods like feature extraction are because they are dynamic and heterogeneous, with
employed for efficient detection [14]. Saba [Link], a wide range of devices, protocols, and settings.
reviewed Internet of Things (IoT) aims to improve lives IDS needs to be able to function well in a variety of
by offering intelligent devices and applications, but network contexts without producing false alarms or
security risks remain a major concern. Deep learning interruptions[19].
model-based anomaly-based intrusion detection sys- Challenge 4: Resource Restrictions: The imple-
tems can improve IoT security by identifying patterns mentation of IDS necessitates substantial resources,
and facilitating smooth detection based on anoma- including hardware, software, and human knowledge.
lies [15]. Dhanya K. A.a [Link], UNSW-NB15 dataset It may be difficult for organizations to allocate enough
reveals that Decision Tree classifier outperforms resources.[20]
other ensemble models in detecting network attacks, Challenge 5: Anomaly Detection: Anomaly-based
with KNearest Neighbour classifier showing the best intrusion detection systems (IDS) can effectively
results . Srikanthyadav Moraboena [Link] deep learning discover unknown threats by detecting deviations
approach for network intrusion detection using a from typical activity. Nevertheless, they frequently
Symmetric Deep Autoencoder (SDAE) for unattended have trouble telling the difference between malicious
function instruction. It also presents a deep research activity and acceptable deviations, which might result
categorization model using stacked SDAEs, based on in missed detections or false alarms[21].
classification of Network Security Laboratory’s Knowl- Challenge 6 High Data Volume:Due to the enor-
edge Discovery in Databases and Canadian Institute mous volumes of data generated by modern networks,
for Cybersecurity’s Intrusion Detection System data it is difficult for IDS to efficiently monitor and handle all
sets. Zhendong Wang [Link], research develops an network traffic in real-time. Because of resource lim-
integrated deep intrusion detection model based on itations, this may lead to missed events or delays in
SDAE-ELM to improve network security by reducing detection[22].
training time and classification accuracy. The model Challenge 7 Encrypted communication: Because
also enhances host intrusion detection accuracy by encryption is so widely used, especially Transport
97
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
Layer Security (TLS), intrusion detection systems (IDS) 3 Research Methodology
have a hard time looking through encrypted commu- The design, implementation, and evaluation of ef-
nication to look for dangerous content. Attackers may ficient intrusion detection systems (IDS) follow a
use encryption to conceal their actions from being methodical process in the research methodology for
discovered. network intrusion detection utilizing machine learning
2.1 Discuss the Cyber Security Attacks (ML) and deep learning (DL) models on cyber security
Cybersecurity attacks represent serious risks to en- attacks[25]. ML and DL models are chosen based
terprises, including ransomware, phishing, malware, on performance, scalability, and [Link]
DDoS, SQL injection, and insider threats. Input valida- efficacy of the trained models in identifying cyber
tion and web application firewalls are implemented, security threats is assessed by applying the proper
employees are trained to recognize phishing emails, validation methodologies. In order to evaluate the
antivirus software is updated frequently, DDoS mitiga- efficacy of various models, comparative analysis is per-
tion services are deployed, regular data backups are formed, taking into account measures like accuracy,
made to reduce the risk of ransomware, and strong precision, recall, and F1-score. In [26]The findings
access controls are put in place to reduce insider are analyzed in light of the goals of the study and the
threats[23]. To further protect against any breaches, body of current literature, offering perceptions into
companies should apply data loss prevention tech- the advantages and disadvantages of ML/DL-based
niques and regularly train staff members on security intrusion detection systems. Ultimately, recommenda-
awareness. By using these countermeasures, compa- tions and conclusions are provided for further study
nies can strengthen their entire security posture and and real-world use of network intrusion detection
cyber attack resistance[24]. systems[27]. Figure 1 represents the problem that
is first specified, along with the kinds of cyberattacks
that need to be found and the performance indicators
that will be employed in the assessment process[28].
98
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
A thorough assessment of the literature is done to 3.2 Datasets IDS
find previous studies, datasets, and methods, which Datasets are crucial for training and assessing intru-
serve as the study’s foundation. Data is obtained sion detection systems, providing network traffic data
and preprocessed for model training, with feature from various sources. The quality and variety of these
selection and engineering techniques used to improve datasets significantly impact the system’s effective-
intrusion detection[29]. ness. Common datasets include malware infections,
DoS, DDoS, and SQL injections[33]. Researchers
3.1 The reality mining dataset
preprocess these datasets to manage missing values,
The Reality Mining scheme corresponds to the biggest
normalize features, and balance class distributions.
cellular mobile trial yet tried in the academic world.
Labeled samples of a variety of cyberattacks, in-
An unparalleled quantity of information on individual
cluding malware infections, Denial of Service (DoS),
performance is gathered and cluster communications
Distributed Denial of Service (DDoS), SQL injection,
that we arrange on any missing and building acces-
and more, are commonly included in datasets for
sible to the universal educational community[30]. At
intrusion detection[34]. NSL-KDD, UNSW-NB15, and
the end of the trial, this dataset will include more
CICIDS2017 are a few frequently utilized datasets that
than fifty thousand hours roughly sixty years of
offer a variety of attack scenarios and network traffic
uninterrupted information on everyday individual
characteristics.
performance[31]. In an editorial on the Reality Mining
project in December’s matter of New Scientist, famous 3.3 Research Challenges During this
communal system forecaster and Harvard professor Research
David Laser was referenced saying that this investi- A number of difficulties could come up while studying
gation will transform the field of communal system how well deep learning and machine learning algo-
investigation[32]. rithms work in cyber security. Lack of a systematic
dataset: This study brought to light the lack of a
current dataset reflecting new attacks on contempo-
99
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
Figure 1. Block Diagram of Intrusion Detection System Counter remeasurements Cyber Security Attacks
rary networks[35]. Because these models were not consumed by complex models: Nearly 80% of the
trained with enough attack kinds and patterns, the researcher’s suggested IDS approaches are based on
majority of the offered approaches were unable to extremely complex models that demand a great deal
detect zero-day attacks[36]. An effective IDS model of processing and computational effort. This could
must be tested and validated on a dataset containing lead to additional processing unit overhead, which
both older and more recent attacks. The inclusion would ultimately impair IDS performance[40].
of the maximum number of attacks specification
in a dataset will help the machine learning (ML/DL) 4 EXPERIMENTS
model identify more patterns, which will ultimately To efficiently identify and address cybersecurity
lead to protection against various sorts of maximum threats, intrusion detection systems (IDS) make use of
invasions[37]. 3.2.2 Reduced detection accuracy as a a range of machine learning and deep learning meth-
result of an unbalanced dataset: The current analysis ods. Because machine learning techniques, including
also reveals that, for some attack types, the majority Random Forests and Support Vector Machines (SVMs),
of the suggested IDS approaches show poorer de- can identify malicious or benign network traffic based
tection accuracy than the model’s overall detection on attributes taken from packet headers or payload
accuracy[38]. The dataset’s imbalance is the root data, they are frequently utilized in machine learning
cause of this issue. Compared to attacks with more applications. Strong and capable of managing high-
instances, the detection accuracy of attacks in the low dimensional data, Random Forests outperform SVMs
frequent attacks class is lower[39]. 3.2.3 Resources in defining intricate decision boundaries. Convolu-
100
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
tional neural networks (CNNs) and recurrent neural details. The label 0 indicates nomal fake news while 1
networks (RNNs), two deep learning architectures, represents the real news detection.
have demonstrated potential in improving intrusion
detection system (IDS) capabilities. These algorithms
enable IDS to automatically learn from and analyze
enormous volumes of network data, enabling it to
respond to changing cybersecurity threats.
4.0.1 Machine Learning Algorithms
Figure 3. Data Distributed Categorical Plots
Intrusion Detection Systems (IDS) employ diverse ma-
chine learning methods to efficiently identify and coun-
teract cybersecurity attacks. The Random Forest classi- 4.1 Check Categorial Data Plots of the
fier is a frequently used technique that is renowned for Dataset
its resilience and capacity to handle high-dimensional The distribution and correlations among the categori-
data. Because Random Forests build many decision cal variables in a dataset can be seen through the use
trees and aggregate their predictions, they are highly of categorical data charts. They show information on
effective at identifying anomalies and categorizing net- the frequency and distribution of various categories
work traffic. Another well-liked IDS tool is Support Vec- and include bar, count, and box graphs. Exploratory
tor Machines (SVMs), which have a high degree of ac- data analysis and feature engineering are aided
curacy when separating malicious from legitimate net- by these plots, which show patterns, anomalies, and
work traffic. SVMs can discriminate between malicious possible relationships within categorical variables. Cat-
and benign network behavior because they can draw egorical data distributions can be visually examined
complex decision boundaries in high-dimensional do- by analysts to identify trends, outliers, and problems
mains. The text discusses the trends in the quantity with data quality. These findings can then be used
to inform further data pretreatment and modelling
stages for more reliable and accurate analysis. The
figure 4.2 represents bar graph with the heading
"Attack Categories by Analysis Method" is attached
to the file you submitted. The many techniques for
analyzing cyberattacks are listed on the x-axis. Normal
analysis, reconnaissance, backdoors, exploits, fuzzers,
worms, shellcode, DoS (denial-of-service), and generic
are some of these techniques. The amount of attacks
that, according to the analysis approach, fit into each
category is displayed on the y-axis. The "normal
analysis" bar, for example, indicates that 35,674,667
attacks were examined by standard procedures. The
Figure 2. The label represents fake and real news dataset "reconnaissance" bar indicates that 8,116,642 assaults
data were found using these techniques.
of labels and potential causes of these trends figure 4.2 Histogram to See the Data
4.1. It also discusses the units of labels, such as the Distribution
number of labels on the y-axis and the time scale on Data distribution in the picture you submitted, as it
the x-axis. It also mentions the existence of additional is devoid of labels and information about the context
101
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
in which it is used. I can, however, describe the gen- tive of the distribution. The histogram’s appearance
eral method of visualizing data distribution using his- may also be impacted by the bin size selection.
tograms. A histogram is a graph that shows how a set
4.3 Correletion Matrix
of data is distributed. The most frequent value or the
A correlation matrix is an essential analytical tool for
middle value in the data set is referred to as the center
finding patterns and links between different network
of the distribution. A histogram’s center is usually lo-
traffic variables or features in the context of Intrusion
cated at the bin with the tallest bar. The degree of varia-
Detection Systems (IDS) within cybersecurity. The cor-
tion among the data points is indicated by the distribu-
relation coefficient, which indicates the direction and
tion’s spread. Figure 4.3 shows that histogram with
strength of a linear relationship between two qualities,
is represented by each item in the matrix. Analysts can
identify characteristics that change together, possibly
indicating unusual activity or security risks within the
network, by looking at the correlation matrix. In
Figure 4. Data Distributions Various Plots Figure 5. Correletion Matrix of the Dataset IDS
the figure 4.4 represents correlated features, for
a broader spread shows more data points distributed
instance, may indicate coordinated attacks in network
throughout the value range, whereas a histogram with
traffic analysis, such as a distributed denial-of-service
a narrower spread shows more data points clustered
(DDoS) attack coming from several sources. On the
at the center. The histogram’s form might provide cru-
other hand, weak or negative correlations may draw
cial details regarding the data’s distribution. A symmet-
attention to a variety of activities or healthy network
rical histogram, for instance, indicates that the data is
activity. By focusing on suspicious patterns or events
dispersed equally around the center. a histogram that
that diverge from typical network activity, security
is distorted, with lopsided bars The histogram’s look
analysts may detect and mitigate cybersecurity risks
can vary depending on how many bins are used. While
more effectively thanks to this expertise. Correla-
fewer bins can make it easier to observe the general
tion matrices also help with feature selection and
shape, more bins can offer a more thorough perspec-
dimensionality reduction, which directs the creation
102
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
and refinement of machine learning models used in selection. The trade-off between recall and precision
intrusion detection systems. Analysts can increase de- at various thresholds is represented by the curve. The
tection accuracy, simplify the model training process, best applications of the precision-recall curve are in
and improve interpretability by detecting features two-class classification issues. Alternative methods
that are strongly linked or redundant. It is imperative of visualization might be more suitable for problems
to take into account the constraints of correlation involving multiple classes. The figure 4.6 shows
analysis, including its incapacity to identify nonlinear
correlations.
4.4 Support Vector Machine (SVM)
The Support Vector Machine (SVM) technique is widely
recognized for its effectiveness in classification and
regression applications. It performs especially well
in high-dimensional spaces and when the number of
features exceeds the number of samples. With the use
of kernel functions that facilitate the efficient handling
of nonlinear decision boundaries, support vector
machines (SVMs) search for the ideal hyperplane in
the feature space that divides various classes. Despite
their strength, support vector machines (SVMs) are
less appropriate for noisy data because to their pro-
cessing expenses, particularly when dealing with huge
datasets and their tendency to struggle when classes
overlap heavily. The curve indicating that the model Figure 7. Confusion Matrix Support Vector Machine (SVM)
Performance
that classification cccuracy is calculated by dividing
the total number of accurate predictions by the total
number of predictions made. Greater performance
overall is indicated by a higher value. By combining
the values on the diagonal of the matrix and dividing
the result by the total of all the values in the confusion
Figure 6. Results of Support Vector Machine (SVM) matrix, you may compute it. It focuses on how well the
Performance Evaluation
model can recognize positive cases. By dividing the
total number of genuine positives and false positives
may be sacrificing some recall in favor of precision.
by the number of true positives, it is computed. This
Recall will rise (the model will find more positive cases)
is the ratio of accurately predicted abnormal cases
when the threshold for identifying a case as positive
(bottom left cell) to the total number of predicted
is dropped, but precision will fall (some of the cases
abnormal instances (bottom row) in the confusion
identified as positive will actually be negative). In con-
matrix. SVM is a machine learning technique that
trast, recall will fall (the model will miss more positive
can be applied to applications involving classification.
examples) when the threshold is raised, but precision
Finding a hyperplane that divides the data points
will increase (the model will identify fewer cases as
of one class from another class is how it operates.
positive, but the ones it does classify will be more
The percentage of data points that an SVM model
likely to be positive). The model’s recall and precision
properly classifies serves as a gauge for its accuracy.
may be impacted by the categorization threshold
103
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
a model has a high precision, it is good at classifying
only the relevant cases as positive. The precision for
class 0 in the example is 1.00, indicating that all of the
data points that were predicted to be class 0 were, in
fact, class 0. The percentage of real positive cases that
the model successfully detected is represented by
this. When a model has a high recall, it is effective in
identifying all pertinent cases. The model accurately
identified all of the actual class 0 data items in the
case, as indicated by the recall of 1.00 for class 0.
The confusion matrix appears that the model is doing
Figure 8. SVM Algorithms Performance Compared Various
Cyber Security Attacks
The SVM model’s training parameters are represented
by the x-axis, most likely. For example, it may display
alternative values for the regularization parameter
or distinct kernel functions utilized by the SVM. On a
scale from 0 to 1, the y-axis shows how accurate the
SVM model is. When the model assigns a value of 1,
all of the data points are correctly classified.
4.5 KNN Algorithm
KNN algorithm straightforward conceptual structure,
K-Nearest Neighbors (KNN) is incredibly useful, partic-
ularly when dealing with non-uniform decision limits.
KNN is especially useful for pattern identification,
anomaly detection, and recommendation systems
Figure 10. Algorithms Performance Compared Various
because it is predicated on the idea that comparable
Cyber Security Attacks
instances typically have similar results. However, it can
be limited by its computational requirements during
a good job of classifying the data based on the high
testing, particularly when dealing with large datasets,
precision, recall, and F1-score for each class in this
and its sensitivity to redundant or unnecessary infor-
case. The quantity of courses: When it comes to multi-
mation. The figure 4.8 shows that the percentage of
class classification challenges involving more than two
classes, the study provides further information. The
remaining data: The precision, recall, and F1-score
for the minority class may be deceptive if the data
is unbalanced, meaning that one class has a much
higher number of data points than the others. The
x-axis, which has the title "Test Number," most likely
alludes to the several assessment sets that were used
Figure 9. Results of KNN Algorithm Performance Evaluation to gauge the effectiveness of the model. Accuracy
is the label for the y-axis, which has a range of 0 to
positive forecasts that came true as predicted. When 1. The performance improves with a greater value.
104
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
straight line in the upper left corner of the graph,
indicating that the model is able to correctly classify all
positive cases (high recall) and all of the cases that the
model classified as positive are actually positive (high
precision). The model accurately categorizes positive
cases in the upper left corner, but trades precision
and recall. A good model has a high precision and
recall curve. A statistic known as the area under
Figure 11. KNNAlgorithms Performance Compared Various
Cyber Security Attacks
At about test number 5, this test nearly reaches 1.0,
suggesting that it has the highest overall accuracy. It
keeps up a high level of accuracy throughout all of the
assessments. Compared to Test 1, this test’s overall
accuracy is lower. Accuracy seems to vary more over
the course of the evaluations, rising and falling with
varying test numbers.
4.6 Logistic Regression
When there is a linear relationship between the target
variables and the characteristics, logistic regression, a
mainstay of classification algorithms, performs excep-
tionally well. It is extremely useful in industries like Figure 13. KNN Algorithms Performance Compared Various
credit scoring and healthcare analytics since it can pro- Cyber Security Attacks
vide probability for outcomes. Its simplicity does have
a drawback, though, as it is limited to linear decision the curve (AUC) can be used to summarise a model’s
limits and has trouble handling complex data linkages. overall performance. A better model is one with a
higher AUC. The precision and recall of the model can
be impacted by the categorization threshold selection.
The precision versus recall trade-off at various levels
is represented by the curve. Logistics Regression
algorithms represents 0 and 1 based of confusion
matrix. The models show thier performance on
various types of data of cyber security attacks dataset
Figure 12. Results of Logistics Regression Algorithm
Performance Evaluation
of intrusion detection. Logistic regression techniques’
performance varies depending on the data type and
The figure 4.11 x-axis of the curve represents the the quality of features. It’s most effective in linearly
recall, which is the proportion of positive cases that separable data and basic decision boundaries, but
were correctly identified by the model; the y-axis may be less effective in high-dimensional data or
represents the precision, which is the proportion of complex attacks. The training dataset and features
the model’s predicted positive cases that were actually also impact its effectiveness.
positive. An ideal precision-recall curve would be a
105
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
Figure 14. Logistics Regression Algorithms Performance
Compared Various Cyber Security Attacks
4.7 GNB Algorithms
Gaussian Naive Bayes (GNB) is a simple and effective
algorithm that finds use in classification applications,
especially those that involve high-dimensional data. Figure 16. GNB Algorithm Confusion Matrix Performanc
Its efficacy in numerous applications, ranging from
text classification to spam filtering, is undeniable, de-
spite the assumption of feature independence, which
may not always hold true in real-world data. Gaus-
Figure 15. GNB Algorithm Performance Evaluation Figure 17. GNB Algorithms Performance Compared Various
Cyber Security Attacks
sian Naive Bayes (GNB) algorithm is a probabilistic
classification method based on Bayes’ theorem. GNB
algorithm performance show the accuracy precision
0.88, recall 1.00 and f1-score 0.89 resprectively. GNB The performance of Gaussian Naive Bayes (GNB)
is straightforward, it has shown to be successful algorithms varies depending on the type of cyberat-
in a variety of classification problems, particularly tack. Due to its ease of use and effectiveness, GNB
when the feature space is Gaussian distributed and is a good fit for managing high-dimensional data,
continuous. The probability density function of the which is frequently encountered in cyber security
Gaussian distribution for each characteristic is used applications. But with coupled or non-Gaussian dis-
in GNB to determine the likelihood of a sample falling tributed features, its performance may be affected
into a given class. GNB’s performance on the Con- by the assumption that features are independent,
fusion Matrix depends on the type of cyber security which may not always hold true. When attack patterns
attack. Its efficiency and simplicity make it suitable for are discernible and classes are well-separated, GNB
high-dimensional data. However, it can deteriorate typically performs well. However, it might not be able
with complex features or non-Gaussian distributions. to withstand extremely complex attacks or those with
minute variances.
106
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
4.8 Deep Learning Algorithms models remain resilient and efficient in a range of
4.8.1 CNN Model application scenarios. The Confusion Matrix of
In the field of deep learning, convolutional neural
networks (CNNs) have become a mainstay, espe-
cially because of their exceptional performance in
image-related tasks. Using a sequence of convolu-
tional layers, CNNs automatically extract hierarchical
information from input images and identify patterns
and spatial correlations. CNNs are very good at
tasks like object detection, picture segmentation,
and image classification because of this hierarchical
feature extraction process. Together with innovations
like transfer learning, their capacity to automatically
learn representations from raw data has enabled
breakthroughs in a variety of industries, including
autonomous driving and healthcare. CNNs are
quite powerful, but they need a lot of labeled data
to train, and their intricate structures might cause
overfitting, which means you have to use cautious
Figure 19. CNN Model Confusion Matrix
regularization strategies and architectural design
decisions. Convolutional Neural Network (CNN)
Convolutional Neural Network (CNN) models provides
a comprehensive evaluation of their classification
accuracy and error types, allowing stakeholders to
identify areas for improvement, fine-tune model
parameters, and enhance their effectiveness in tasks
like object detection, semantic segmentation, and
picture recognition. The above diagram represents
Figure 18. CNN Model Performance Evaluation
models are evaluated for performance using metrics
such as accuracy, precision, recall, and F1-score.
CNNs are excellent at tasks like object detection,
segmentation, and picture classification because they
can automatically learn hierarchical features. Crucial
assessment methods encompass confusion matrix
analysis, which sheds light on classification errors,
and cross-validation, which guarantees generalization
across various datasets. Furthermore, methods such Figure 20. CNN Model Performance Compared Various
as precision-recall curves and ROC curves aid in the Cyber Security Attacks
selection and fine-tuning of models by visualizing the
trade-offs between true positive rate and false positive the CNN model performance on confusion matrix.
rate. It is imperative to conduct routine performance CNNs also show promise in identifying anomalies
monitoring and validation to guarantee that CNN in network traffic patterns, highlighting peculiar be-
haviors that could indicate possible attacks such as
107
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
denial-of-service (DoS) attacks or attempts at data and flexible in a variety of cyber security and other
exfiltration. CNNs are incredibly flexible instruments applications. Furthermore, methods like precision-
for cyber security protection measures because of
their versatility and capacity to recognize complex
patterns.
4.8.2 LSTM Model
Recurrent neural networks (RNNs) have been modified
to create Long Short-Term Memory (LSTM) networks,
which are meant to capture long-term dependencies
in sequential data and solve the vanishing gradient
issue that conventional RNNs have. In order to accom-
plish this, LSTMs integrate memory cells with gating
mechanisms, which over time selectively preserve or
delete information. They become crucial in tasks like
speech recognition, time series forecasting, and natu-
ral language processing (NLP) because of their ability
to efficiently model temporal dependencies. LSTMs
are a key tool in the field of sequential data analysis
because of their capacity to handle sequences of Figure 22. LSTM Model Confusion Matrix
different lengths and capture context over long time
spans. Long Short-Term Memory (LSTM) models recall curves and receiver operating characteristic
(ROC) curves help to visualize trade-offs between
true positive rate and false positive rate, which helps
with model selection and optimization. Frequent
performance review guarantees that LSTMs continue
to be effective and flexible in a variety of cyber security
and other applications. Long Short-Term Memory
Figure 21. LSTM Model Performance Evaluation
are evaluated by measuring their F1-score, accuracy,
precision, and recall. Natural language processing,
time series prediction, and anomaly detection are just
a few of the applications where LSTMs shine. These
tasks involve the examination of sequential data. Eval-
uation methods include confusion matrix analysis to
comprehend classification errors and cross-validation
to guarantee robustness across various datasets. Figure 23. LSTM Model Performance Compared Various
Furthermore, methods like precision-recall curves Cyber Security Attacks
and receiver operating characteristic (ROC) curves
help to visualize trade-offs between true positive (LSTM) models effectively identify threats through a
rate and false positive rate, which helps with model comparative diagram comparing their performance
selection and optimization. Frequent performance across various cyber security attacks. They can iden-
review guarantees that LSTMs continue to be effective tify trends and abnormalities, aiding stakeholders in
108
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
making informed decisions about defense strategies flows lost at the start of the time interval, followed
and threat mitigation efforts. This visual comparison by a fall. It’s hard to interpret the graph precisely
highlights their strengths and limitations. without more details. It’s possible, nevertheless, that
the graph illustrates how successful a DDoS mitigation
4.8.3 Autoencoder Model Performance system is. The abrupt spike in DDoS flows lost can be
Neural networks classified as autoencoders are em- a sign that a DDoS attack was detected and stopped
ployed for unsupervised learning tasks, specifically by the system. The attack may have ended if the loss
in denoising, data compression, and feature learn- of DDoS flows decreased. It looks as though the
ing. They are made up of a decoder network that
uses the latent space representation created by the
encoder network to recover the original input, and
an encoder network that compresses the input data.
Autoencoders enable effective data compression and
visualization by facilitating dimensionality reduction
and feature extraction through the learning of a
compact representation of the input data. Moreover,
autoencoders can be trained to rebuild clean samples
from noisy inputs, thereby denoising corrupted data.
Their adaptability and capacity to derive meaningful
representations from unlabeled data make them
indispensable in a number of fields, such as recom-
mendation systems, anomaly detection, and image Figure 25. Autoencoder Detect DoS Flows Loss
generation. The graph shows the total number
y-axis extends from 0 to 400,000. With values rising at
a progressively faster rate from left to right, the x-axis
seems to be non-linear. On the graph, a single line is
drawn. From left to right, the line tends upward, but
it seems to flatten out near the higher y-axis. The
Figure 24. Autoencoder Detect DDoS Flows Loss
of DDoS attacks lost over time, with a sharp rise in
DDoS flows at the start and a fall at the end of the
time interval. The graph’s y-axis displays the quantity
of DDoS flows lost, and the x-axis represents time.
Although the x-axis scale is unlabeled, it seems to span Figure 26. Autoencoder Detect DDoS Flows Loss
a little time interval—possibly seconds or milliseconds.
The graph displays a sharp rise in the quantity of DDoS graph shows the total number of mistakes made
109
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
during training, with a declining trend indicating less
mistakes as training progressed. The y-axis represents
errors, with labels likely multiples of 100,000. This
indicates the model is becoming more proficient and
picking up new skills. A confusion matrix is a table
Figure 27. Autoencoder Model Performance Evaluation
that displays how well an algorithm performs while
classifying various classes. It is applied to statistics and
machine learning. The actual classes are represented Figure 28. Autoencoder Model Confusion Matrix
by the rows in the confusion matrix you submitted,
and the anticipated classes are represented by the
columns. The number of data points in each category
is indicated by the numbers in the table. For instance,
the number of data points that were both class 0
in reality and class 0 in the algorithm’s prediction is
3,567,467 in the top left cell. The amount of accurate
forecasts is displayed on the table’s diagonal. In this
instance, more class 0 data points (3,567,467) than
class 1 data points (811,664) were predicted by the
model. The model’s performance is further detailed Figure 29. Autoencoder Model Performance Compared
by looking at the metrics at the bottom of the table: Various Cyber Security Attacks
accuracy, precision, recall, and F1 score. The indicator
of a model’s ability to discriminate across classes
confusion matrices measure reconstruction error, not
is called AUC, or Area Under the Curve. Its AUC is
classification accuracy. Threshold dependence affects
69.0% in this scenario. The confusion matrix is a
interpretation, with lower thresholds indicating more
tool used in autoencoders to assess an error in the
successful reconstructions but potentially introducing
reconstruction of initial input data. It represents the
noise.
degree to which the autoencoder can reconstruct the
data, with actual labels in rows and predicted labels 5 Conclusion and Future Direction
in columns. The data points in the table are classified Intrusion Detection Systems (IDS) employ an array of
as either abnormal or normal, with 68.6% of them machine learning and deep learning techniques to
showing effective rebuilding. Reconstructions are proficiently identify and address cybersecurity threats.
categorized using a threshold; however, the precise Because they can identify malicious or benign network
threshold value is not given. The autoencoder’s ca- traffic based on attributes taken from packet headers
pacity to reconstruct the original data for every class or payload data, machine learning techniques like
is evaluated by the confusion matrix. Autoencoder Random Forests and Support Vector Machines (SVMs)
110
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
are commonly utilized. Random Forests are resilient References
and effective with high-dimensional data, whereas [1] H. Liu and B. Lang, “Machine learning and deep learn-
Support Vector Machines are superior at drawing ing methods for intrusion detection systems: A survey,”
intricate decision borders. Convolutional neural net- Applied Sciences, p. 4396, 2019.
works (CNNs) and recurrent neural networks (RNNs),
[2] L. Ashiku and C. Dagli, “Network intrusion detection sys-
two deep learning architectures, have demonstrated
tem using deep learning,” Procedia Computer Science,
potential in improving intrusion detection system (IDS) pp. 185, 239–247, 2021.
capabilities. CNNs are useful for tasks like detecting
anomalies in network traffic patterns or recognizing [3] P. Kumar, A. A. Kumar, C. Sahayakingsly, and
A. Udayakumar, “Analysis of intrusion detection in
virus signatures in packet payloads because they
cyber attacks using deep learning neural networks,”
are skilled at extracting spatial information from
Peer-to-Peer Networking and Applications, vol. 14,
network traffic data. Because RNNs especially Long
pp. 2565–2584, 2021.
Short-Term Memory (LSTM) network are good at
capturing temporal dependencies, they can identify [4] Z. Ahmad, A. Shahid Khan, C. Wai Shiang, J. Abdullah,
minute, time-varying patterns that could be signs of and F. Ahmad, “Network intrusion detection system: A
cyberthreats. These algorithms enable IDS to auto- systematic study of machine learning and deep learn-
ing approaches,” Transactions on Emerging Telecommu-
matically learn from and analyze enormous volumes
nications Technologies, vol. 14, p. e4150, 2021.
of network data, enabling it to respond to changing
cybersecurity threats. Deep learning models CNN [5] M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Jan-
and LSTM accuracy rate is highest as compare to all icke, “Deep learning for cyber security intrusion detec-
the algorithms. Machin learning some models poor tion: Approaches, datasets, and comparative study,”
performance on the testing data of cyber security Journal of Information Security and Applications, vol. 50,
attacks dataset. p. 102419, 2022.
[6] I. F. Kilincer, F. Ertam, and A. Sengur, “Machine learn-
Author Contributions ing methods for cyber security intrusion detection:
Irfanullah Khan, Waqas Ahmad,Shah Hussain Datasets and comparative study,” Computer Networks,
Bangash: Conceptualization, Methodology, Soft- vol. 188, p. 107840, 2021.
ware Waqas Ahmad , Junaid Khan, Shah Hussain
[7] N. Thapa, Z. Liu, D. B. Kc, B. Gokaraju, and K. Roy, “Com-
Bangash: Data curation, Writing- Original draft
parison of machine learning and deep learning models
preparation. Irfanullah Khan , Junaid Khan, Khalid
for network intrusion detection systems,” Future Inter-
Hameed: Visualization, Investigation. Irfanullah net, vol. 12, p. 167, 2020.
Khan, Muhammad Asad Iftikhar, Khalid Hameed:
Supervision.: Waqas Ahmad, Muhammad Asad [8] M. A. Ferrag, L. Maglaras, H. Janicke, and R. Smith, “Deep
learning techniques for cyber security intrusion detec-
Iftikhar: Software, Validation. Muhammad Asad
tion: A detailed analysis,” in 6th International Symposium
Iftikhar, Shah Hussain Bangash: Writing- Reviewing
for ICS & SCADA Cyber Security Research 2019, pp. 110,
and Editing
102817, 2019.
Compliance with Ethical Standards [9] R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachan-
It is declared that all authors don’t have any conflict of dran, A. Al-Nemrat, and S. Venkatraman, “Deep learn-
interest. It is also declared that this article does not ing approach for intelligent intrusion detection system,”
contain any studies with human participants or ani- IEEE Access, vol. 7, pp. 41525–41550, 2019.
mals performed by any of the authors. Furthermore, [10] B. Susilo and R. F. Sari, “Intrusion detection in iot
informed consent was obtained from all individual networks using deep learning algorithm,” Information,
participants included in the study. vol. 11, p. 279, 2020.
111
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
[11] J. Asharf, N. Moustafa, H. Khurshid, E. Debie, W. Haider, [20] T. Ullah, E. G. Hussnain, W. Ahmad, G. Sikander, and
and A. Wahab, “A review of intrusion detection systems M. Ashfaq, “An efficient machine learning based mul-
using machine and deep learning in internet of things: ticlass cyber attacks classification and prediction,” The
Challenges, solutions and future directions,” Electronics, Sciencetech, vol. 4, 2023.
vol. 9, p. 1177, 2020.
[21] R. Khan, L. Jan, S. Khan, M. H. Zafar, W. Ahmad, and
[12] L. Liu, P. Wang, J. Lin, and L. Liu, “Intrusion detection of G. Husnain, “An effective algorithm in uplink massive
imbalanced network traffic based on machine learning mimo systems for pilot decontamination,” Results in En-
and deep learning,” IEEE Access, vol. 9, pp. 7550–7563, gineering, p. 101873, 2024.
2020.
[22] T. Saba, A. Rehman, T. Sadad, H. Kolivand, and S. A. Ba-
[13] N. Saeed, W. Ahmad, and D. M. S. Bhatti, “Localization haj, “Anomaly-based intrusion detection system for iot
of vehicular ad-hoc networks with rss based distance networks through deep learning model,” Computers and
estimation,” in 2018 International Conference on Comput- Electrical Engineering, pp. 99, 107810, 2022.
ing, Mathematics and Engineering Technologies (iCoMET),
[23] M. S. Elsayed, N.-A. Le-Khac, S. Dev, and A. D. Jurcut,
pp. 1–6, 2018.
“Ddosnet: A deep-learning model for detecting network
[14] I. H. Sarker, Y. B. Abushark, F. Alsolami, and A. I. Khan, attacks,” in 2020 IEEE 21st International Symposium on
“Intrudtree: a machine learning based cyber security "A World of Wireless, Mobile and Multimedia Networks"
intrusion detection model,” Symmetry, vol. 12, p. 754, (WoWMoM), pp. 391–396, 2020.
2020.
[24] I. Ullah, M. Yasir, I. U. Haq, G. Husnain, S. U. Islam,
[15] W. Ahmad, G. Husnain, S. Ahmed, F. Aadil, S. Lim, et al., W. Ahmad, and S. Rizwan, “Performance evaluation of
“Received signal strength-based localization for vehi- secured virtual private network based on dynamic mul-
cle distance estimation in vehicular ad hoc networks tipoint virtual private network,” in Proceedings of 1st In-
(vanets),” Journal of Sensors, 2023. ternational Conference on Computing Technologies, Tools
and Applications, pp. 26–35, 2023.
[16] M. Imran, N. Haider, M. Shoaib, I. Razzak, et al., “An intel-
ligent and efficient network intrusion detection system [25] T. A. Tang, L. Mhamdi, D. McLernon, S. A. R. Zaidi, and
using deep learning,” Computers and Electrical Engineer- M. Ghogho, “Deep learning approach for network intru-
ing, vol. 99, p. 107764, 2022. sion detection in software defined networking,” in 2016
International Conference on Wireless Networks and Mobile
[17] S. H. Bangash, D. Khan, A. Ishtiaq, M. Imad, M. Tahir,
Communications (WINCOM), pp. 258–263, 2016.
W. Ahmad, G. Husnain, and L. Jan, “Integrating machine
learning and deep learning approaches for efficient mal- [26] Z. Wang, Y. Liu, D. He, and S. Chan, “Intrusion detection
ware detection in iot-based smart cities,” Journal of Com- methods based on integrated deep learning model,”
puting & Biomedical Informatics, vol. 05, pp. 280–299, Computers & Security, vol. 103, p. 102177, 2021.
2023.
[27] G. Kocher and G. Kumar, “Machine learning and deep
[18] W. Ahmad, S. Ahmed, N. Sheeraz, A. Khan, A. Ishtiaq, learning methods for intrusion detection systems: re-
and M. Saba, “Localization error computation for rssi cent developments and challenges,” Soft Computing,
based positioning system in vanets,” in 2019 Interna- vol. 25, pp. 9731–9763, 2021.
tional Conference on Advances in the Emerging Computing
[28] N. A. Awad, “Computers, materials & continua,”
Technologies (AECT), pp. 1–6, 2020.
Medicine, vol. 67, 2021.
[19] D. Akgun, S. Hizal, and U. Cavusoglu, “A new ddos at-
[29] L. Abualigah and A. J. Dulaimi, “A novel feature selec-
tacks intrusion detection model based on deep learn-
tion method for data mining tasks using hybrid sine co-
ing for cybersecurity,” Computers & Security, vol. 118,
sine algorithm and genetic algorithm,” Cluster Comput-
p. 102748, 2022.
ing, vol. 24, pp. 2161–2176, 2021.
112
VFAST Transactions on Software Engineering Volume 12, Issue 2, 2024
[30] N. Tiwari, N. K. Singh, R. Singh, and R. Rameshwar, “Iden-
tifying potential churners through predictive analysis:
evaluation using pro-active-attrition management logis-
tic regression,” International Journal of Technology Trans-
fer and Commercialisation, vol. 18, pp. 439–461, 2021.
[31] P. Edastama, A. Dudhat, and G. Maulani, “Use of data
warehouse and data mining for academic data: A case
study at a national university,” International Journal of Cy-
ber and IT Service Management, vol. 1, pp. 206–215, 2021.
[32] R. Hou, X. Ye, H. B. O. Zaki, and N. A. B. Omar, “Mar-
keting decision support system based on data mining
technology,” Applied Sciences, vol. 13, p. 4315, 2023.
[33] Y. Fu, Y. Du, Z. Cao, Q. Li, and W. Xiang, “A deep learning
model for network intrusion detection with imbalanced
data,” Electronics, vol. 1, p. 898, 2022.
[34] H. Su, H. Sun, J. Zhu, S. Wang, and Y. Li, “Bat: Deep learn-
ing methods on network intrusion detection using nsl-
kdd dataset,” IEEE Access, 2020.
[35] F. Ateş et al., “Determination of vehicle type by image
classification methods for a sample traffic intersection
in isparta province,” in Proceedings of the International
Conference on Artificial Intelligence and Applied Mathe-
matics in Engineering, 2021.
[36] S. Rawat et al., “Intrusion detection systems using classi-
cal machine learning techniques vs integrated unsuper-
vised feature learning and deep neural network,” Inter-
net Technology, vol. 5, 2022.
[37] P. L. S. Jayalaxmi et al., “Machine and deep learning so-
lutions for intrusion detection and prevention in iots: A
survey,” IEEE Access, vol. 10, pp. 121173–121192, 2022.
[38] Y. K. Saheed et al., “A machine learning-based intrusion
detection for detecting internet of things network at-
tacks,” Alexandria Engineering Journal, vol. 12, pp. 9395–
9409, 2022.
[39] V. Dutta et al., “A deep learning ensemble for network
anomaly and cyber-attack detection,” Journal of Sensor,
vol. 20, p. 4583, 2020.
[40] H. Yang, L. Cheng, and M. C. Chuah, “Deep-learning-
based network intrusion detection for scada systems,”
in IEEE Conference on Communications and Network Secu-
rity, 2019.
113