Applying Deep Learning Techniques for Network Traffic Classification: A Comparison Study on the NSL-KDD Dataset | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Applying Deep Learning Techniques for Network Traffic Classification: A Comparison Study on the NSL-KDD Dataset Issam Trrad This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-3869444/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract The escalating intricacy and refinement of network attacks require the implementation of advanced methodologies in network security and intrusion detection. This study centers on the utilization of machine learning techniques for the categorization of network traffic, specifically employing the NSL-KDD dataset. This study investigates the efficacy of various classifiers, namely Linear Support Vector Machine (SVM), Quadratic SVM, K-Nearest Neighbor (kNN), and Long Short-Term Memory (LSTM), for the precise detection of anomalous network activity. The data is preprocessed through various techniques, including one-hot encoding and normalization, in order to enhance the performance of the model. Feature selection is utilized as a means to improve the outcomes of classification. By conducting a thorough evaluation and analysis, we present an assessment of the classifiers' performance in terms of precision, recall, and F1-score. The findings demonstrate the potential application of machine learning techniques in the field of network security, underscoring the significance of carefully choosing suitable algorithms and preprocessing approaches to achieve efficient intrusion detection. The results of our study make a significant contribution to the advancement of intrusion detection systems based on machine learning. These findings offer valuable insights for both network security practitioners and researchers in the field. Network traffic Intrusion detection system (IDS) NSL-KDD dataset Machine learning Network security Figures Figure 1 Figure 2 Figure 3 Figure 4 Figure 5 Figure 6 Figure 7 1 Introduction Internet access and various forms of smart technology are increasingly widely acknowledged as necessities today. It is possible that people's beliefs and assumptions will change as a result of increased interaction among them. Every country wants to have the most modern gadgets and the best services available. This is prompting efforts in many parts of the world to create "smart cities." The research undertaken by Chatterjee et al. [ 7 ] provides insight into how well system security and confidentiality provisions in India's proposed smart cities mesh with citizens' use of IT-enabled services. An old saying states, "Security today is a myth." Culture plays a significant role in shaping how people of various backgrounds define safety. Simply put, the term "e-communication," which also refers to "electronic communication," covers a wide variety of situations. When people and their environments are able to have meaningful conversations, we call that "communication." To put it another way, communication allows for the unhindered exchange of thoughts and information between people. These messages can be conveyed via a wide range of channels, from spoken words and body language to ciphers and facial expressions. With the advent of so many different types of Webs 2.0, global compatibility of technical standards is growing, as reported by Kar et al. [ 21 ]. This made it critical to set up and keep reliable lines of communication open. Example: As [ 36 ] demonstrates, it is difficult for individuals to fully grasp security provisions and risks due to the mashup of IT terminology and financial flow. According to Ever et al. [ 15 ], artificial intelligence has come a long way in the last few decades. Animals have been shown to excel at a number of commonplace tasks where humans fall short. Networking and security are two aspects of digital technology that have issues that need fixing. The amount of information that can be transmitted in a single second has increased exponentially in recent years. We have seen the development of detection, prevention, and classification machine learning algorithms during the past two decades. The underlying goal of these developments has been to improve the approach taken to challenges in the real world. For businesses to function, communication between employees is crucial for building relationships and sharing information. Internet traffic is proportional to the number of individuals using the internet at any given moment. In this article, we have authors such as A [ 26 ]. The traffic generated by any given user has nothing to do with the total number of users who access a given web server. Distinguishing unusual trends in the traffic data from the norm requires statistical analysis. Due to the proliferation of digital information, the volume of network traffic has skyrocketed in the past decade. There have been efforts to make communication protocols safer and easier to use by conceiving and building them to be more user-friendly. These initiatives have been taken to improve the accessibility of existing communication technologies. The adaptability of the protocols makes them vulnerable to manipulation by cybercriminals. To paraphrase Lee and Stolfo.[ 27 ], "intrusion detection" is a crucial step in protecting systems from such assaults. Issues related to web attacks can be identified and resolved with the help of AI. Identification of potential intruders is made easier with the help of machine learning techniques such as the convolutional neural networks described by Ding and Zhai [ 13 ], the hybrid data mining approach described by [ 3 ], and the genetic algorithm with a vectorized fitness function described by [ 31 ]. Success is measured in part by how well a solution meets the requirements of a fitness function. A fitness score is assigned to each numerical string in genetic algorithms based on the evaluation the algorithm does. No matter how high or low your score is, it doesn't matter. It's useful for characterizing how well-suited a certain solution is. In this study, we'll take a quick look at how effectively various machine learning algorithms spot intrusion attempts and grade their effectiveness. The objective of this work is to conduct this kind of analysis. The research aims to meet a need in the intrusion detection systems sector by integrating the findings of numerous artificial intelligence (AI) and machine learning (ML) techniques for data collection (IDS). The highest quality outputs were achieved by employing the appropriate settings for each algorithm. These objectives served as the compass by which we navigated our investigation into the subject at hand. Classification challenges, whether they are binary or involve more than two classes, require extensive hypothesis formulation and evaluation utilizing both univariate and multivariate techniques to provide greater detail on the multiple attack pathways and the relevance of intrusion detection. That holds true regardless of how many distinct classes are in play. Study several different classifiers, including the K-nearest-neighbour technique, linear and quadratic support vector machine classifiers with linear kernels, and long short-term memory. We will use the k-nearest-neighbour classifier and the multi-layer perceptron to study the DoS, Probe, R2L, and U2R assaults, as well as the more common ones. Each form of assault will also have its efficacy evaluated. The study consists of an introductory section, a review of the relevant literature, and a discussion of information systems, cyber security challenges, and AI-based algorithms designed to alleviate these issues. Univariate and bivariate analysis are just two examples of the research methods covered in Section 3 's overview. Discussion of the results can be found in Section 4 , which comes right after. As we mentioned in Section 5 , we'll be talking about the study's theoretical and practical ramifications later. In Section 5 , we report the results and discuss the study's implications moving forward. 2 Related Works Modern society would crumble without the inventions and innovations made possible by technology. Due to the advent of new technologies like cordless phones, satellite TV, cloud computing, and SpaceX, the fundamental tenets upon which information systems are based have been shattered, causing a dramatic shift in their purpose. When trying to analyse and fix complex business issues, it's proven crucial to get perspectives from a wide range of areas and sources. With the proliferation of digital services, the protection of personal information has become a critical concern. Every successful company today needs a secure data storage facility and an effective data backup strategy. Any business, no matter how big or small, requires at least one employee who can assess and fully understand information technology (IT) [ 2 ]. Information can be understood as anything that can be directly viewed in the physical environment. Items can refer to anything from a collection of numbers to a visual representation of a person's tastes and preferences. The two gentlemen of [ 8 ] the story could be based on a novel, or it could be inspired by many other pieces of literature. It may be purely a mental construct. Books and other written resources at a library are worth their weight in gold when it comes to gaining knowledge. The end is not in sight... There's more to come... More to come... To be continued: [ 33 ] many people use libraries and other book-related data sources as if they were information systems. The two authors [ 24 ], it is possible for IT infrastructure issues to arise, and [ 5 ] discuss some of the more common ones. A number of factors, including the system's quality, characteristics, retrieval methods, etc., could be to blame for these issues. Information quality and reliability [ 14 ], the need for users to maintain some measure of privacy and control over their data, and the services that rely on it all contribute to the difficulty of ensuring the cybersecurity of information systems. As the frequency of malicious cyber activity rises, the ability to detect breaches is becoming increasingly important. Tonge et al. [ 40 ] released their work in 2013. Everyone, not just those who work in IT, has a responsibility to help keep the internet a safe and trustworthy place to conduct business. Cheval There is no industry immune to the devastation that may be caused by a cyberattack today. Three devoted Muslims: [ 22 ] Automatic learning has progressed at the same time that cybersecurity monitoring systems have improved. According to Reshmi, the connection between Al and ML has turned possessive and intrusive. Making a decision requires hardly any time at all. Many algorithms and intrusion detection systems can be used to safeguard data locally or in the cloud. And as for [ 10 ], the Internet's early pattern-matching algorithms have been used to detect malicious cyber activities. The aforementioned pattern-matching job was executed using an algorithm developed by [ 43 ]. Therefore, the algorithms were analysed thoroughly. Yin implemented methods from the Boyer-Moore string search algorithm (BMH), the Aho-Corasick algorithm (AC-BM), and the BMH (2012). The efficacy of the model's application is dependent on the precision of the algorithm's results. The naive technique, the Knuth-Morris-Pratt algorithm, and the Rabin-Karp algorithm are all merged into one in [ 9 ] work on intrusion detection. The internet makes it possible to disseminate data in bite-sized chunks. There are applications in these bundles that can scan networks for issues and predict traffic flows with high precision. These records are stored in files with the. pcap extension. Having access to PCAP files is helpful because they can identify serious issues in a network that need immediate action. When PCAP files were added to the datasets, the algorithms' accuracy jumped by 16%. Network traffic is growing exponentially as the number of people using smartphones and other connected devices rises. Since some attributes are found to be duplicated, detection takes longer. The use of IG (information gain) and gain measurement in our performance evaluation is inspired by [ 1 ] analysis of correlation-based feature selection algorithms. In a 2013 paper by Chae et al. proposed improved feature selection methods by weighting characteristics equally across all classes and all situations. Before the data has been cleaned and prepared, knowledge discovery cannot take place. Well-prepared data is essential for trustworthy and accurate analysis. Those lawyers' names are [ 32 ]. The study evaluates the efficacy of three assault detection techniques, including decision trees, random forests, and rule-based classifiers. Be sure to involve Poonam and the rest of the team. To prove the efficacy of outlier detection, Kumar et al. [ 23 ] sought to develop a state-of-the-art model for intrusion detection capable of both outlier identification and clustering methodologies simultaneously. After laying the groundwork in [ 11 ], Denatious and John [ 11 ] describe a variety of data mining techniques. These aid in the development of trustworthy ID models and offensive tactics. Now the user can establish a protected network. The ease with which attacks can be discovered using the right optimizers and learning rate is a function of the datasets and features employed [ 18 ] are just an example. In order to function at maximum efficiency, optimizers are required. On the contrary, AdaBoost-based models were taken into account by [ 17 ]. The detection rates and overall efficacy of the logistic model are both quite high. To make sure the model hasn't been "tweaked" too much to fit the data, cross-validation is used. For text classification, the "k-nearest neighbour" (KNN) technique is used. A straightforward method of identifying the most common forms of online criminality. Experiments have demonstrated that KNN can increase model accuracy while simultaneously decreasing the false-positive rate. KNN's computational improvements make it simpler to factor in a user's prior behaviour when classifying features. For example, Liao and Vemuri [ 28 ] show that the kNN classifier is effective in finding hackers who have broken into a system. Ingre and Yadav [ 19 ] and Tavallaee et al. [ 38 ] outline the shortcomings of the original KDD dataset, which inspired the creation of the NSL KDD dataset. By and large, the BAT model created by Su et al. (2020) is a traffic anomaly detection model. A prolonged effect like this allows us to benefit from enhanced cognition and memory for a longer period of time. The data obtained by attentional processes is useful for scheduling resources in a network. Due to its adaptable structure, traffic data can be gathered in the proper context. In order to better display the data required to conceal unnecessary traits, [ 25 ] method is preferred. Data was reduced by 80.4%, and training time was cut by 40%. The duration of the examinations was reduced by 70%. The NSL KDD dataset was largely influenced by the work of [ 19 ] and Tavallaee et al. [ 38 ]. In conclusion, [ 37 ] BAT model is a traffic anomaly detection model. A prolonged effect like this allows us to benefit from enhanced cognition and memory for a longer period of time. The data obtained by attentional processes is useful for scheduling resources in a network. Due to its adaptable structure, traffic data can be gathered in the proper context. In order to better display the data required to conceal unnecessary traits, [ 25 ] method is preferred. Data was reduced by 80.4%, and training time was cut by 40%. The duration of the examinations was reduced by 70%. Compared to the control CNN and RNN models, the BAT model fared better. The need for a more comprehensive database is discussed further below. As a result, classifiers were created to sort the data into meaningful groups. The working accuracy of the model improved while using a large enough dataset. The researchers didn't concentrate on a specific population to keep the study's costs in check. More frequent data is required to increase the accuracy of the model. This kind of thinking might be categorized as prejudice. After getting rid of all the duplicates in the original dataset, we were able to update NSL-KDD. Careful consideration was given to including information from all potential difficulties in the new collection. Proportionally inverse to how much of the old KDD data set was incorporated into the new records. In order to improve the accuracy of the classification models, it is recommended to apply multiple models to the dataset. By combining data from multiple studies into one cohesive collection, we may more confidently draw conclusions. 3 Methods and Materials 3.1 Dataset This experiment makes use of the NSL-KDD benchmark dataset rather than the original KDD Cup 99 dataset because the former provides a better baseline for determining the efficacy of the model that we developed. This is because the latter resolved some issues that had been extensively discussed in the past. Even though this dataset still has the problems we talked about earlier, academics who study intrusion detection use it often, so we think it is real. In addition to regular flow patterns, the collection also contains a wide variety of unusual occurrences. There are five distinct types, including denial of service attacks, regular traffic attacks, U2R attacks, R2L attacks, probing assaults, and regular attacks. Their breakdown is shown in Table I. DoS attacks, regular traffic attacks, U2R attacks, R2L attacks, and probing assaults are all part of it. There are 41 features included in each record of the original NSL-KDD dataset; however, not all of these features can be accurately represented while being trained. The data must be preprocessed, and the symbolic characteristics of the protocol type, service, and flag must be extended using 1-N encoding. Lastly, the flag's symbolic characteristics have to be encoded. The processed data yields a total of 122 features, which are comprised of three protocol types, seventy services, and eleven flags. These features are extracted from the data. The NSL-KDD dataset will be normalized to the interval [0, 1] after the following step, which is to perform a max-mix operation on it. Table 1 breakdown of five distinct types of attacks Category Training set Test set Attacks Dos 45927 7458 U2R 52 67 R2L 995 2887 Probe 11656 2421 Normal 67343 9711 Total 125973 22544 According to Dhanabal and Shantharajah [ 12 ], the primary forms of multi-class attacks can be broken down into four categories: Denial-of-service, abbreviated as DOS, refers to an offensive strategy that interferes with service. Attacks of this sort have the potential to bring a complete halt to all modes of transportation. Because this is the case, no data will be transmitted to the network. For instance, the availability of things may not always be up to date during huge sales events at Amazon, Flipkart, or any other e-commerce company. As a result of this, customers may try to check out with items that other customers have already purchased. DOS assaults comprise a wide variety of methods, such as mail bombs and Neptune attacks. An R2L attack comes from a remote computer and seeks to acquire illegal access through the user. This type of attack is also known as a man-in-the-middle assault. Being Satan, being a warez master, or attempting to guess the CVVs of credit and debit cards in order to access online accounts are all examples of activities that fall under this category. An attempt to gain full control of a network, as well as all of the information contained inside it, is referred to as a "User-to-Root (U2R) attack." As the name of this type of attack suggests, the objective is to establish oneself as the only primary user so that information can be exploited commercially. There are exploits such as buffer overflow, Perl, SQL attacks, and others, to name a few examples. Both overt actions of surveillance and covert inquiries might be included in the process of probing. This kind of assault is carried out with the intention of gleaning as much information and data as possible from protected networks. The information may include a person's name and gender in addition to their financial details and other sensitive data such as passwords, portsweeps, saints, and so on. 3.2 Data Pre-Processing It is necessary to perform preprocessing on the data before building a model using deep learning. When constructing a deep learning project, it is not a given that we will locate data that is both clean and well-formatted in every instance. Because of this, it is essential to thoroughly clean and format the data before carrying out any operation on it. The process of changing raw data into a format that can be utilized by an algorithm for machine learning or deep learning is referred to as "data preparation," and it is the first step and, perhaps, the most critical stage in the development of a model. It's a great idea to use game-changing technologies like AI and DL to make better decisions and help companies grow, but these benefits won't be realized unless the right data processing methods are also put in place. Many of the algorithms have difficulty functioning properly after categorical data has been included in a machine learning or deep learning model. Both the input and output variables of the categorical data need to be converted into their numerical equivalents. If you are involved in any kind of data science, you have most likely come across the term "one-hot encoding." Sklearn's definition is "to encode categorical integer features using a one-hot technique." To be more specific, it means "to encode categorical integer features using a one-hot technique." The same thing happens with deep learning and other types of machine learning algorithms due to the fact that a machine can only comprehend numbers and cannot interpret the text that begins with. One-hot encoding is a crucial step in the process of preparing the categorical data variables to be submitted to machine learning and deep learning methods, which both have the potential to improve the accuracy of a model's predictions and classifications. This potential improvement is made possible by the use of techniques from the fields of machine learning and deep learning. To ensure that machine learning models work properly, categorical data must be preprocessed using a single hot encoding. Then, a unique binary feature for each possible category is made, and the value 1 is given to the feature of each sample that corresponds to the category it came from. 3.3 Feature Selection For the most accurate results, there was an emphasis placed on feature selection. Models that have been trained on relevant characteristics perform the best when it comes to classifying test sets. The following table presents the findings obtained by categorizing data according to four different approaches: The Chi-Square test was used to choose the features for the binary classification. The following are the steps that were taken after that: First, one needs to make the hypothesis more specific. Since there is no correlation between the two variables, HO is correct. The alternative hypothesis states that the two variables could be interdependent on one another. This possibility exists as well (Hl). Second Using the TCP protocol type, separate the samples that resulted in an intrusion into a separate table from the samples that did not result in an intrusion. Third, projections were constructed by analysing past information and data. Chi-square statistics were utilized to establish the top 20 factors that were responsible for the attacks after it was found that there was a substantial association between the two. Fig .1 Feature selection of the whole dataset 3.4 Data Standardization Normalization of the dataset Over-fitting and missing values are eliminated when the dataset is normalized. Because of the uniformity brought about by normalization, any kind of wrongdoing can be readily prevented in the future. If you want to normalize certain numbers that change over time, you can use a scale from 0 to 1 as your starting point. Moreover, normalization aids in avoiding discrepancies when giving weights to the parameters. Reducing the number of dimensions used to describe something is called "feature reduction." In Ingre, Yadav, and Soni, correlation feature selection was utilized (2017). It was found that the binary class classification generated significantly more output than the five attack categories. 3.5 Evaluation Metrics 3.5.1 F1 Score The F1 score is less well-known than the P and R scores. It is calculated by harmonically averaging P and R scores. Zero indicates poor performance on both precision and recall. If they get a 1, they did well on both. $$\varvec{F}1 \varvec{S}\varvec{c}\varvec{o}\varvec{r}\varvec{e}=\frac{2\varvec{T}\varvec{P}}{(2\varvec{T}\varvec{P}+\varvec{F}\varvec{P}+\varvec{F}\varvec{N}\varvec{N})}$$ 1 3.5.2 Accuracy The precision of our model can be thought of as the fraction of total predictions that turn out to be accurate. To do this, first, tally up the number of accurate positive (TP) and negative (TN) projections, and then divide that figure by the sum of all forecasts made (including accurate and inaccurate ones) (FP, FN). $$\varvec{A}\varvec{c}\varvec{c}\varvec{u}\varvec{a}\varvec{r}\varvec{c}\varvec{y}=\frac{(\varvec{T}\varvec{P}+\varvec{T}\varvec{N})}{(\varvec{T}\varvec{P}+\varvec{T}\varvec{N}+\varvec{F}\varvec{P}+\varvec{F}\varvec{N})}$$ 2 Precision ranges from zero to one. Both extremes—perfect and completely wrong predictions—are possible. Example: Our model won't make mistakes if it can forecast everything (positive or negative). Since the numerator and denominator are equal, the precision is 1. If our system constantly makes incorrect predictions, the sum of true positives and negatives and the difference between zero and a positive number must always be zero. Inverting labels can improve prediction accuracy if it drops below 0.5. Technically, accuracy is 0.5–1%. However, data bias makes accuracy a poor statistic. When positive and negative labels are far apart, accuracy alone might be misleading. Consider that 95 of 100 samples are Class 0, while 5 are Class 1. A "dummy" model that predicts Class 0 with 95% accuracy must be effective. Because only Class 0 is predictable. Its unreliable outcomes make it impossible to evaluate the model's efficacy. If we only measured this model's correctness, stakeholders and consumers would receive an inefficient and unreliable service. 3.5.3 Precision Data scientists often get around problems with accuracy by using precision, recall, and specificity in their analysis. Looking at the accuracy, one can determine what fraction of optimistic predictions came true. To calculate the accuracy rate, take the total number of positive predictions and divide it by the percentage of those forecasts that turned out to be correct (TP, FP). $$\varvec{P}\varvec{r}\varvec{e}\varvec{c}\varvec{i}\varvec{s}\varvec{i}\varvec{o}\varvec{n}=\frac{\varvec{T}\varvec{P}}{(\varvec{T}\varvec{P}+\varvec{F}\varvec{P})}$$ 3 3.5.4 Recall Recall, much like accuracy, determines how many of the questions asked were answered correctly. In order to arrive at this result, we divide the total number of samples that tested positive by the overall number of samples that tested positive (TP, FN). $$\varvec{R}\varvec{e}\varvec{c}\varvec{a}\varvec{l}\varvec{l}=\frac{\varvec{T}\varvec{P}}{(\varvec{T}\varvec{P}+\varvec{F}\varvec{N})} \left(4\right)$$ 3.6 Study Model The suggested algorithm's overall layout is depicted in Fig. 2 , which may be seen here. The goal of these model-based investigations was to make the NSL-KDD dataset easier to read and easier to put into groups. 4 Experiment Result 4.1 Binary Classification Within the framework of the binary categorization system, the only two outcomes that are conceivable are "normal" and "abnormal." A score of 0 indicated that the labels were abnormal, while a value of 1 indicated that they were normal. We employed one-hot coding on attack labels so that we could more accurately map the attacks and categorize them. To successfully decode the information that is being provided to it, one-hot encoding is a necessary step. It does this by converting information into a form that can be read by machines called binary. To ascertain the level of association that existed between the features of the binary class dataset, the Pearson correlation test was carried out. By utilizing Pearson's correlation, we can gain an understanding of the connections that exist between the various continuous variables. Yes (l) and no are the only two choices that can be made in response to the intrusion question (0). As a result, a new dataset was selected for further examination after it was determined which attributes had a correlation of more than 0.5 and after the encoded, one-hot-encoded, and original attack label attributes were merged. 4.1.1 Linear Kernel Support Vector Machine Classifier for Linear and Quadratic Data In this section, the outcomes of employing a Linear Kernel Support Vector Machine (L-SVM) classifier on the linear and quadratic data within the NSL-KDD dataset are presented. The L-SVM classifier is renowned for its efficacy in handling linearly separable data, as it employs a linear decision boundary to distinguish between classes. Table 2 presents the classification report pertaining to the L-SVM classifier. The metrics of precision, recall, and F1-score are presented for both the "abnormal" and "normal" classes. The L-SVM classifier exhibits excellent performance, with precision scores of 0.98 and 0.97 for the "abnormal" and "normal" classes, respectively. Additionally, it demonstrates robust recall scores of 0.97 and 0.98, leading to a well-balanced performance across all categories. The L-SVM classifier achieves an F1-score of 0.97 for the "abnormal" class and 0.98 for the "normal" class. In addition to the L-SVM classifier, we also investigated the Quadratic Support Vector Machine (Q-SVM) classifier, which employs a quadratic decision boundary to effectively handle intricate and non-linearly separable datasets. The classification report for the Q-SVM classifier is presented in Table 3 . It is worth mentioning that the Q-SVM classifier demonstrates a remarkable precision of 1.00 for the "abnormal" class, signifying that all positive predictions are correct. The precision achieved by the "normal" class is 0.95. The Q-SVM classifier exhibits high recall scores of 0.94 for the "abnormal" class and 1.00 for the "normal" class, indicating its strong performance in correctly identifying instances belonging to these classes. The F1-scores obtained for the "abnormal" and "normal" classes are 0.96 and 0.97, respectively. The results of this study demonstrate the efficacy of both the Linear Support Vector Machine (L-SVM) and Quadratic Support Vector Machine (Q-SVM) classifiers in accurately categorizing the linear and quadratic data within the NSL-KDD dataset. The L-SVM classifier exhibits superior performance in accurately representing the attributes of linearly separable data, whereas the Q-SVM classifier showcases its proficiency in addressing intricate, non-linear patterns. The efficacy of the linear support vector machine (L-SVM) classifier in the context of network security is evident, as it demonstrates promising outcomes for intrusion detection. The achieved precision for both the "abnormal" and "normal" classes is high, suggesting a low occurrence of false positives. This implies that the classifier demonstrates a high level of accuracy in correctly predicting instances as either "abnormal" or "normal" in the majority of cases. The recall scores exhibit significance, particularly in relation to the "normal" class. This finding suggests that the L-SVM classifier successfully detects instances of normal network traffic, thereby reducing the occurrence of false negatives. A high recall score pertaining to the "abnormal" class signifies that the classifier is capable of identifying a significant proportion of intrusions. In general, the F1-scores demonstrate a favorable equilibrium between precision and recall for both categories. This indicates that the L-SVM classifier effectively discriminates between regular network traffic and anomalous activity, thereby facilitating the identification of potential intrusions. The utilization of the quadratic support vector machine (Q-SVM) classifier has been shown to exhibit strong and reliable performance in the context of network security applications. The exceptional precision score achieved by the Q-SVM classifier for the "abnormal" class indicates its proficiency in accurately detecting instances of abnormal behavior. The detection of potential intrusions and the maintenance of network security are of utmost importance. The Q-SVM classifier demonstrates effective recognition of legitimate network traffic, resulting in a reduced false positive rate, as indicated by the high precision score for the "normal" class. The exemplary recall score associated with the "normal" class underscores its efficacy in accurately identifying all instances of normal behavior, thereby minimizing the risk of misclassifying legitimate traffic as abnormal. The F1-scores for both classes exhibit robust performance, indicating a harmonious trade-off between precision and recall. This suggests that the Q-SVM classifier has the ability to accurately classify instances in both the "abnormal" and "normal" classes, thereby enhancing the overall efficacy of intrusion detection in a network security setting. Table 2 Liner Support Vector Machine Classification Report L-SVM precision recall f1-score abnormal 0.98 0.97 0.97 normal 0.97 0.98 0.98 Table 3 Quadratic Support Vector Machine Classification Report Q-SVM precision recall f1-score abnormal 1.00 0.94 0.96 normal 0.95 1.00 0.97 4.1.2 Binary Classification using K-Nearest-Neighbor Classifier In this section, the outcomes of utilizing a K-Nearest Neighbor (KNN) classifier for the purpose of conducting binary classification on the NSL-KDD dataset are presented. The K-nearest neighbors (KNN) algorithm is a non-parametric approach that assigns class membership to a given sample by considering its proximity to the nearest neighbors in the feature space. The classification report for the KNN classifier is presented in Table 4 . The metrics of precision, recall, and F1-score are presented for both the "abnormal" and "normal" classes. The K-nearest neighbors (KNN) classifier demonstrates a notable level of precision for both classes, exhibiting a precision rate of 0.98 for the "abnormal" class and 0.97 for the "normal" class. This observation suggests that the KNN classifier exhibits a low rate of false positives, thereby reducing the occurrence of misclassifying normal instances as abnormal, and vice versa. The recall scores are particularly notable, particularly in the "normal" class, where the KNN classifier achieves a flawless recall score of 1.00. This suggests that the classifier successfully detects and categorizes all instances of typical network activity, thereby preventing legitimate traffic from being mistakenly classified as anomalous. The K-nearest neighbors (KNN) classifier demonstrates a recall score of 0.98 for the "abnormal" category, signifying its proficiency in accurately detecting a substantial number of abnormal instances. The F1-scores for both classes demonstrate an equilibrium between precision and recall, yielding an overall F1-score of 0.97 for the "abnormal" class and 0.98 for the "normal" class. This study showcases the efficacy of the K-nearest neighbors (KNN) classifier in accurately categorizing instances and discerning between normal and abnormal network behavior. The findings of the binary classification utilizing the KNN classifier highlight its efficacy as a dependable approach for detecting intrusions in network security. The commendable precision and recall scores exhibited by the system highlight its capacity to effectively discern between normal and abnormal network traffic, thereby enhancing the overall efficacy of intrusion detection systems. The K-Nearest Neighbor (KNN) classifier exhibits robust performance in the context of intrusion detection from a network security standpoint. The precision scores for both the "abnormal" and "normal" classes demonstrate a minimal occurrence of false positives. This implies that the accuracy of the KNN classifier in predicting an instance as either "abnormal" or "normal" is high in the majority of cases. The recall scores exhibit noteworthy performance, as evidenced by a perfect recall score of 1.00 for the "normal" class. This suggests that the K-nearest neighbors (KNN) classifier successfully captures all instances of normal network traffic, thereby reducing the occurrence of false negatives. This showcases a proficient capacity to discern authentic network behavior, thereby ensuring that regular traffic is not erroneously categorized as anomalous. The K-nearest neighbors (KNN) classifier demonstrates a recall score of 0.98 for the "abnormal" class, suggesting its efficacy in accurately detecting a substantial portion of abnormal instances. The detection of potential intrusions and the maintenance of network security are of utmost importance. The F1-scores for both classes demonstrate a harmonious trade-off between precision and recall, suggesting a robust overall performance of the KNN classifier in effectively categorizing instances and discerning between normal and abnormal network behavior. Table 4 KNN Classification Report KNN precision recall f1-score abnormal 0.98 0.98 0.97 normal 0.97 1.00 0.98 4.1.3 Binary Classification using Long Short-Term Memory Classifier This section presents the outcomes of employing a Long Short-Term Memory (LSTM) classifier for the purpose of binary classification on the NSL-KDD dataset. The Long Short-Term Memory (LSTM) is a specific variant of the recurrent neural network (RNN) architecture, which has demonstrated its efficacy in effectively capturing sequential patterns and dependencies within datasets. Table 5 presents the evaluation metrics pertaining to the LSTM model. The recall score, F1-score, and precision score are reported in the study. The LSTM classifier exhibits a recall score of 0.989, indicating its proficiency in accurately identifying a significant proportion of true positive instances within the dataset. Accurate identification and detection of intrusions is of utmost importance in this context. The LSTM classifier achieved an F1-score of 0.976, which represents a harmonious trade-off between precision and recall. This implies a robust performance in terms of accurately classifying instances, effectively identifying true positive cases, and minimizing both false positives and false negatives. The LSTM classifier demonstrates a low false positive rate, as evidenced by its precision score of 0.963. The system effectively distinguishes positive instances and reduces the occurrence of misclassifying normal instances as abnormal. Ensuring the reliability of the intrusion detection system and reducing the occurrence of false alarms are crucial factors to consider. The efficacy of the LSTM model in binary classification for intrusion detection on the NSL-KDD dataset is demonstrated by the evaluation metrics presented in Table 5 . The high recall score, F1-score, and precision score of the model indicate its proficiency in accurately categorizing instances and efficiently discerning between normal and abnormal network behavior. The utilization of the LSTM classifier in network security applications is highly advantageous due to its ability to effectively capture sequential patterns and dependencies. This makes it a valuable tool, particularly in scenarios where real-time detection of intrusions is of utmost importance. The performance of the LSTM classifier is deemed exceptional in terms of network security, as evidenced by the evaluation metrics presented in Table 5 . The aforementioned metrics offer valuable insights into the classifier's capacity to accurately classify instances and its overall efficacy in the field of intrusion detection. The recall score, which measures the proportion of true positive instances correctly identified by a network security system, is a crucial metric with a value of 0.989. The high sensitivity of the LSTM classifier is evident in its ability to accurately identify true positive instances, which refer to actual intrusions in the given context. The LSTM classifier demonstrates a recall score of 0.989, indicating its effective ability to detect a substantial number of intrusions within the NSL-KDD dataset, thereby minimizing the occurrence of false negatives. The detection and notification of potential security breaches is of utmost importance. The F1-score, which has a value of 0.976, indicates a well-balanced performance in terms of both precision and recall. The findings suggest that the LSTM classifier effectively balances the task of accurately detecting intrusions while simultaneously minimizing the occurrence of both false positives and false negatives. The high F1-score demonstrates the classifier's efficacy in delivering dependable intrusion detection capabilities for network security applications. The LSTM classifier's precision score of 0.963 highlights its proficiency in minimizing the occurrence of false positives. The data suggests that the classifier demonstrates an accuracy rate of approximately 96.3% in correctly identifying instances as intrusions. The precision score serves as a measure of the classifier's efficacy in minimizing false positives and mitigating unnecessary disruptions resulting from misclassifying regular instances as intrusions. The evaluation metrics presented in Table 5 demonstrate the robust performance of the LSTM model in the context of network security applications. The combined evaluation metrics of high recall score, F1-score, and precision score collectively demonstrate the LSTM classifier's efficacy in accurately identifying and categorizing intrusions, thereby serving as a valuable instrument for augmenting network security. Table 5 Evaluation Metric of the LSTM model Recall Score 0.989 F-1 Score 0.976 Precision Score 0.963 The operational characteristic curve (ROC) serves as a valuable graphical depiction of the diagnostic accuracy of a binary classifier system within the realm of network security. The performance of the classifier system is demonstrated by the ROC curve through the manipulation of the discrimination threshold. The ROC analysis was first introduced in 1941 specifically for military radar sensors. It offers a systematic approach to choosing the most effective models and discarding less effective ones, irrespective of the cost context or class distribution. As a result, it improves the decision-making process. The research incorporates comprehensive analyses of these methodologies. In the realm of network security, there exists a logical and straightforward connection between ROC analysis and cost-benefit analysis of diagnostic options. The ROC curve in Fig. 6 illustrates the performance of the LSTM model in effectively detecting and classifying intrusions. 4.2 Multi-Class Classification The network security framework encompasses a range of attack types, such as Denial of Service (DoS), Probe, Remote-to-Local (R2L), User-to-Root (U2R), and general attacks. In order to facilitate the analysis of the data, we utilized both one-hot encoding and label encoding methodologies. These techniques were employed to convert the dataset into a numerical format, wherein multiple labels were assigned to represent the various categories of assaults. The application of Pearson correlation allowed us to identify the most robust associations among the attributes present in the multi-class dataset. The utilization of Pearson's correlation coefficient facilitated the assessment of the degree of association between variables that are measured on a continuous scale. By employing this methodology, we were able to exploit the dual advantages of the multi-class nature of the data, encompassing multiple attack types, as well as the numerical attributes associated with it. Through the integration of the encoded, one-hot-encoded, and original attack label properties, we successfully identified the variables exhibiting a correlation exceeding 0.5. The aforementioned selection process yielded a more refined dataset that can now be subjected to further scrutiny. 4.2.1 K-Nearest-Neighbor Classifier This section focuses on the utilization of the K-Nearest Neighbor (kNN) classifier for multi-class classification on the NSL-KDD dataset. The k-nearest neighbors (kNN) algorithm is widely utilized in the field of machine learning for the purpose of classifying instances. This algorithm determines the class of an instance by considering its proximity to labeled examples within the feature space. The multi-class classification report for the kNN classifier is presented in Table 6 . The metrics of precision, recall, and F1-score are presented for each class, namely Dos, Probe, R2L, U2R, and Normal. The precision score quantifies the ratio of accurately predicted instances for a particular class, whereas the recall score evaluates the ratio of correctly classified actual instances. The F1-score can be defined as the mathematical average of precision and recall, which offers a well-balanced evaluation of classification effectiveness. The k-nearest neighbors (kNN) classifier exhibits a notable level of precision across the majority of classes. The precision scores obtained for the different attack types are as follows: 0.96 for Denial of Service (DoS), 0.99 for Probing, 0.94 for Remote to Local (R2L), 0.50 for User to Root (U2R), and 0.94 for Normal. The aforementioned scores serve as a measure of the kNN classifier's proficiency in accurately categorizing instances within each respective class. Likewise, the recall scores exhibit a high level of performance, as evidenced by the values of 0.97 for Denial of Service (DoS), 0.99 for Probing, 0.93 for Remote to Local (R2L), 0.87 for User to Root (U2R), and 0.93 for Normal. The obtained scores indicate that the kNN classifier successfully captures a substantial proportion of instances for every class. The classifier's performance is further supported by the F1-scores, which demonstrate values of 0.95 for the Dos category, 0.99 for Probe, 0.93 for R2L, 0.35 for U2R, and 0.97 for Normal. The observed scores exhibit a commendable equilibrium between precision and recall, which suggests that the classifier possesses the ability to accurately classify instances across various classes.In the context of multi-class classification on the NSL-KDD dataset, the kNN classifier demonstrates favorable performance. The effectiveness of the model in distinguishing between various types of network traffic and accurately classifying instances is demonstrated by its high precision, recall, and F1-scores for each class. The performance of the k-nearest neighbors (kNN) classifier in the context of multi-class classification offers valuable insights when considering network security. The presented table displays the metrics of precision, recall, and F1-score for each class, specifically Dos, Probe, R2L, U2R, and Normal. These metrics aid in evaluating the efficacy of the classifier in accurately categorizing instances and offer a comprehensive comprehension of its performance in network security applications. The precision scores represent the ratio of accurately predicted instances for each class. The kNN classifier demonstrates strong performance in accurately identifying instances within each class, as evidenced by high precision scores. Specifically, Dos achieves a precision score of 0.96, Probe achieves 0.99, R2L achieves 0.94, U2R achieves 0.50, and Normal achieves 0.94. The minimization of misclassification of instances is of utmost importance in the context of network security, as it enhances the reliability of intrusion detection. The recall scores serve as an indicator of the classifier's capacity to accurately identify and include true instances of every class. The k-nearest neighbors (kNN) classifier exhibits high recall scores, specifically achieving values of 0.97 for the Denial of Service (Dos) category, 0.99 for Probe, 0.93 for Remote to Local (R2L), 0.87 for User to Root (U2R), and 0.93 for Normal. The obtained scores demonstrate the classifier's efficacy in accurately detecting and classifying various types of network traffic by effectively identifying a substantial proportion of instances within each class. The F1-scores offer a comprehensive evaluation of the classifier's effectiveness by taking into account both precision and recall. The k-nearest neighbors (kNN) classifier demonstrates notable performance in terms of F1-scores, exhibiting values of 0.95 for Denial of Service (Dos), 0.99 for Probe, 0.93 for Remote to Local (R2L), 0.35 for User to Root (U2R), and 0.97 for Normal. The observed scores suggest a favorable equilibrium between precision and recall, which signifies the classifier's efficacy in correctly categorizing instances while minimizing the occurrence of both false positives and false negatives. The findings presented in Table 6 indicate that the k-nearest neighbors (kNN) classifier exhibits strong performance in the context of multi-class classification for network security applications. The high precision, recall, and F1-scores exhibited by the model across various classes highlight its ability to accurately classify instances and make a significant contribution to the effectiveness of intrusion detection. Table 6 kNN Multi-Class Classification Report precision recall f1-score support Dos 0.96 0.97 0.95 11484 Probe 0.99 0.99 0.99 2947 R2L 0.94 0.93 0.93 274 U2R 0.50 0.87 0.35 15 Normal 0.94 0.93 0.97 16774 4.2.2 Multi-Layer Perceptron Classifier The effective implementation of deep learning in the field of network security is largely dependent on the application of neural networks. Neural networks are comprised of interconnected neurons, which serve as pivotal components in the processing of information and the formulation of decisions. Neural networks in the field of network security serve as algorithms for identifying and resolving problems, enabling accurate categorization of network traffic. The utilization of a linear hyper-plane enables the establishment of a basic two-classification system. However, the incorporation of hidden layers becomes imperative when confronted with diverse network behaviors. The Adam optimization algorithm was utilized in our study to determine the optimal configuration for the sequential model. In order to enhance the process of acquiring knowledge, we integrated a softmax activation function and employed a loss function that is derived from categorical cross-entropy. The model underwent training for a total of one hundred epochs in order to improve its precision. After taking into account all relevant factors, the model's overall accuracy was determined to be 99.23%. The visualization of the relationship between accuracy and decay over time is depicted in Fig. 8. 5 Conclusion The present study investigates the utilization of machine learning methodologies within the domain of network security, with a specific emphasis on the categorization of network traffic utilizing the NSL-KDD dataset. The results underscore the efficacy of different classifiers in the context of intrusion detection and network security. The study revealed that the Linear Support Vector Machine (SVM) classifier exhibited notable precision and recall scores, suggesting its proficiency in accurately categorizing instances of abnormal and normal network behavior. In a similar vein, the Quadratic Support Vector Machine (SVM) classifier exhibited exceptional precision in identifying abnormal instances and achieved flawless recall in detecting normal instances. This characteristic renders it a highly valuable instrument for capturing diverse forms of network traffic. The assessment of the K-Nearest Neighbor (kNN) classifier demonstrated high precision and recall scores across various classes, highlighting its potential for effectively classifying multiple categories in intrusion detection and network security contexts. In addition, the Long Short-Term Memory (LSTM) classifier demonstrated exceptional recall and F1-scores due to its capacity to effectively capture sequential patterns and dependencies. This characteristic renders it a valuable resource for effectively identifying intrusions within network traffic. Preprocessing techniques, such as one-hot encoding and normalization, have been instrumental in improving the efficacy of machine learning models in the domain of network security. Moreover, the inclusion of feature selection was found to be crucial in attaining optimal outcomes in classification. In summary, this study showcases the capabilities of machine learning methodologies in the classification of network traffic and identification of intrusions, thereby playing a crucial role in upholding network security. The efficacy of different classifiers, such as Linear SVM, Quadratic SVM, kNN, and LSTM, was demonstrated in multiple domains of network security. By utilizing these models, organizations can augment their capacity to identify and address potential threats, ultimately strengthening network security and protecting vital information. It is imperative to recognize that the primary focus of this study was directed towards the NSL-KDD dataset. However, conducting additional research utilizing a wide range of datasets and employing advanced machine learning algorithms will provide further insights into the field of network security and intrusion detection. The results presented in this study offer a significant contribution to the ongoing endeavors in the development of reliable intrusion detection systems based on machine learning techniques. We express our aspiration that these findings serve as a catalyst for additional research and progress in network security. Declarations Conflict of interest: all authors certify that they have no affiliations with or involvement in any organization or entity with financial or non-financial interest in the subject matter or materials discussed in this manuscript . Funding The authors did not receive support from any organization for the submitted work. Author Contributions Issam Trrad. Wrote the main manuscript text and prepared all figures. And reviewed the manuscript. Ethical Approval We certify that informed consent was obtained from all participants. Data availability The data used in this study are available upon request from the corresponding author. The data will be made available securely and confidentially, consistent with applicable laws and regulations. Any requests for data will be reviewed on a case-by-case basis to ensure that the data are being used for legitimate research purposes. References Alrawashdeh K, Purdy C (2016) Toward an online anomaly intrusion detection system based on deep learning, in 2016 15th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 195–200 Alter S (1996) Information Systems: A Management Perspective, 2nd edn. The Benjamin/Cummings, Menlo Park, CA Bhattacharjee PS, Fujail AKM, Begum SA (2017) Intrusion detection system for NSL-KDD data set using vectorised fitness function in genetic algorithm, Advanced Computer Sciences and Technologies, vol. 10, no. 2, pp. 235–246, Boyce MW, Duma KM, Hettinger LJ, Malone TB, Wilson DP, Lockett-Reynolds J (2011) Human performance in cybersecurity: A research agenda, in Proceedings of the Human Factors and Ergonomics Society Annual Meeting, vol. 55, pp. 1115–1119 Brancheau JC, Wetherbe JC (1987) Key issues in information systems management MIS Quarterly, pp. 23–45, Chae H-s, Jo B-o, Choi S-H, Park T-k (2013) Feature selection for intrusion detection using NSL-KDD. Recent Adv Comput Sci 20132:184–187 Chatterjee S, Kar AK, Gupta M (2018) Alignment of IT authority and citizens of proposed smart cities in India: System security and privacy perspective. Global J Flex Syst Manage 19(1):95–107 Checkland P, Holwell S (1998) Information, Systems, and Information Systems. John Wiley & Sons, Chichester Dagar V, Prakash V, Bhatia T (2016) Analysis of pattern matching algorithms in network intrusion detection systems, in 2nd International Conference on Advances in Computing, Communication, & Automation (ICACCA)(Fall), 2016, pp. 1–5 Deepu T, Ravi V (2021) Supply chain digitalization: An integrated MCDM approach for inter-organizational information systems selection in an electronic supply chain. Int J Inform Manage Data Insights 1(2):100038 Denatious DK, John A (2012) Survey on data mining techniques to enhance intrusion detection, in 2012 International Conference on Computer Communication and Informatics, pp. 1–5 Dhanabal L, Shantharajah S (2015) Int J Adv Res Comput Communication Eng 4(6):446–452A study on NSL-KDD dataset for intrusion detection system based on classification algorithms, Ding Y, Zhai Y (2018) Intrusion detection system for NSL-KDD dataset using convolutional neural networks, in Proceedings of the 2nd International Conference on Computer Science and Artificial Intelligence, 2018, pp. 81–85 Elmaghraby AS, Losavio MM (2014) Cyber security challenges in smart cities: Safety, security and privacy. J Adv Res 5(4):491–497 Ever YK, Sekeroglu B, Dimililer K (2019) Classification analysis of intrusion detection on NSL-KDD using machine learning algorithms, in International Conference on Mobile Web and Intelligent Information Systems, pp. 111–122 Gurung S, Ghose MK, Subedi A (2019) Int J Comput Netw Inform Secur 11(3):8–14Deep learning approach on network intrusion detection system using NSL-KDD dataset, Hu W, Hu W, Maybank S (2008) Adaboost-based algorithm for network intrusion detection, IEEE Transactions on Systems, Man, and Cybernetics, Part B (Cybernetics), vol. 38, no. 2, pp. 577–583, Imran HM, Abdullah AB, Hussain M, Palaniappan S, Ahmad I (2012) Intrusions detection based on optimum features subset and efficient dataset selection. Int J Eng Innovative Technol 2(6):265–270 Ingre B, Yadav A (2015) Performance analysis of NSL-KDD dataset using ANN, in 2015 International Conference on Signal Processing and Communication Engineering Systems, pp. 92–96 Ingre B, Yadav A, Soni AK (2017) Decision tree-based intrusion detection system for NSL-KDD dataset, in International Conference on Information and Communication Technology for Intelligent Systems, pp. 207–218 Kar AK, Ilavarasan V, Gupta M, Janssen M, Kothari R (2019) Moving beyond smart cities: Digital nations for social innovation & sustainability, Information Systems Frontiers, vol. 21, no. 3, pp. 495–501, Khan M, Ibrahim, Hussain A (2021) An exploratory prioritization of factors affecting current state of information security in Pakistani university libraries. Int J Inform Manage Data Insights 1(2):100015 Kumar V, Chauhan H, Panwar D (2013) K-means clustering approach to analyze NSL-KDD intrusion detection dataset. Int J Soft Comput Eng (IJSCE), ISSN 2231–2307, Kunz W, Rittel HW (1970) Issues as elements of information systems, vol. 131, Citeseer, Lakhina S, Joseph S, Verma B (2010) Feature reduction using principal component analysis for effective anomaly-based intrusion detection on NSL-KDD, Lazarevic A, Ertoz L, Kumar V, Ozgur A, Srivastava J (2003) A comparative study of anomaly detection schemes in network intrusion detection, in Proceedings of the 2003 SIAM International Conference on Data Mining, pp. 25–36 Lee W, Stolfo S (1998) Data mining approaches for intrusion detection, in Proceedings of the 7th USENIX Security Symposium, Liao Y, Vemuri VR (2002) Use of k-nearest neighbor classifier for intrusion detection. Computers & Security 21(5):439–448 Meena G, Choudhary RR (2017) A review paper on IDS classification using KDD 99 and NSL KDD dataset in WEKA, in 2017 International Conference on Computer, Communications and Electronics (Comptelix), pp. 553–558 Mustafa SZ, Kar AK, Janssen M (2020) Understanding the impact of digital service failure on users: Integrating Tan’s failure and DeLone and McLean’s success model. Int J Inf Manag 53:102119 Parsaei MR, Rostami SM, Javidan R (2016) Int J Adv Comput Sci Appl 7(6):20–25A hybrid data mining approach for intrusion detection on imbalanced NSL-KDD dataset, Paulauskas N, Auskalnis J (2017) Analysis of data pre-processing influence on intrusion detection using NSL-KDD dataset, in 2017 Open Conference of Electrical, Electronic and Information Sciences (eStream), pp. 1–5 Reddy GN, Reddy G (2014) A study of cyber security challenges and its emerging trends on latest technologies, arXiv preprint arXiv:1402.1842, Reshmi T (2021) Information security breaches due to ransomware attacks-a systematic literature review. Int J Inform Manage Data Insights 1(2):100013 Revathi S, Malathi A (2013) Int J Eng Res Technol (IJERT) 2(12):1848–1853A detailed analysis on NSL-KDD dataset using various machine learning techniques for intrusion detection, Shahim A (2021) Security of the digital transformation, Computers & Security, vol. 108, 102345, Su T, Sun H, Zhu J, Wang S, Li Y (2020) IEEE Access 8:29575–29585Bat: Deep learning methods on network intrusion detection using NSL-KDD dataset, Tavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the KDD Cup 99 data set, in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, pp. 1–6 Tiwari S, Palivela H, Kumar P (2022) Classification and identification of partial outage in transmission lines using deep learning, in Recent Innovations in Computing. Springer, pp 155–167 Tonge AM, Kasture SS, Chaudhari SR (2013) Cyber security: Challenges for society-literature review. IOSR J Comput Eng 2(12):67–75 Wu P-f, Shen H-j (2012) The research and amelioration of pattern-matching algorithm in intrusion detection system, in 2012 IEEE 14th International Conference on High Performance Computing and Communication & 2012 IEEE 9th International Conference on Embedded Software and Systems, pp. 1712–1715 Yin (2012) An improved BM pattern matching algorithm in intrusion detection system, in Applied Mechanics and Materials, vol. 148, Trans Tech Publ., pp. 1145–1148 Zhang H (2009) Design of intrusion detection system based on a new pattern matching algorithm, in 2009 International Conference on Computer Engineering and Technology, vol. 1, pp. 545–548 Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-3869444","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":267423003,"identity":"5e76e93f-03a7-4c47-8097-45201e94f23c","order_by":0,"name":"Issam Trrad","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA30lEQVRIiWNgGAWjYBACNghpw8zAkABmMjbAWDi1gPWwpZGgBWIN22EGZC34AZ9877MPP8rOs/O3JwMZDDayGw4wPHyA32HsxjN7zt1mljjzDMhgSDMGakk2wK+FjZmBt+02M8ONBGMGHobDiUAtaRKEtDD+bTvHLH8j/TPjH4b/xGlh5m07wGxwI8eYmYfhADFa0piZZc4lMxueeVPMLGOQbDzzMAG/yDcfY2Z8U2aXLHc8fTPjmwo72b7jPYkP8GmBgWQIBTKemSeBGB0Mdkhs9gNEaRkFo2AUjIIRAwA110KK3AOkBQAAAABJRU5ErkJggg==","orcid":"","institution":"Jadara University","correspondingAuthor":true,"prefix":"","firstName":"Issam","middleName":"","lastName":"Trrad","suffix":""}],"badges":[],"createdAt":"2024-01-16 10:14:11","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-3869444/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-3869444/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":49797245,"identity":"8bce8c8f-f4de-4f66-81a1-7437a0689586","added_by":"auto","created_at":"2024-01-18 07:37:52","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":24882,"visible":true,"origin":"","legend":"\u003cp\u003eFeature selection of the whole dataset\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/41d8bda13bb34f6f3e6a8dff.png"},{"id":49797527,"identity":"6fbd4ac3-f84d-4810-9577-f7695268cf69","added_by":"auto","created_at":"2024-01-18 07:45:52","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":61217,"visible":true,"origin":"","legend":"\u003cp\u003eStudy flow chart\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/22929933944f88bdf227cfcb.png"},{"id":49798548,"identity":"44726d4a-61b3-4dbb-8357-4da74a465be5","added_by":"auto","created_at":"2024-01-18 08:01:52","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":177831,"visible":true,"origin":"","legend":"\u003cp\u003eQSVM-Classifier Binary Set\u003c/p\u003e","description":"","filename":"3.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/ede2cfd3251781ebdfc987e1.png"},{"id":49797526,"identity":"0bd08adf-fcf2-42e0-b8ee-a2c6b2733ba2","added_by":"auto","created_at":"2024-01-18 07:45:52","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":100703,"visible":true,"origin":"","legend":"\u003cp\u003ekNN Classifier Binary Set\u003c/p\u003e","description":"","filename":"4.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/19ab3bed019993963066775e.png"},{"id":49797246,"identity":"51d77423-66db-408c-a3c1-5e12b6ef4908","added_by":"auto","created_at":"2024-01-18 07:37:52","extension":"png","order_by":5,"title":"Figure 5","display":"","copyAsset":false,"role":"figure","size":99889,"visible":true,"origin":"","legend":"\u003cp\u003eVisualization of Training and Testing Dataset (A) Accuracy Vs Epoch (B) Loss Vs Epoch\u003c/p\u003e","description":"","filename":"5.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/8f60d2161b1ee21208d8f13c.png"},{"id":49798104,"identity":"b2d47e9a-63c6-4e6e-89ca-4596ea4036c1","added_by":"auto","created_at":"2024-01-18 07:53:52","extension":"png","order_by":6,"title":"Figure 6","display":"","copyAsset":false,"role":"figure","size":31320,"visible":true,"origin":"","legend":"\u003cp\u003eReceiver Operating Characteristic Curve\u003c/p\u003e","description":"","filename":"6.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/c0b0207ae6a3e894846bde1c.png"},{"id":49797251,"identity":"f3d926fe-ec8e-4522-88b3-762b6a07f9bd","added_by":"auto","created_at":"2024-01-18 07:37:52","extension":"png","order_by":7,"title":"Figure 7","display":"","copyAsset":false,"role":"figure","size":69837,"visible":true,"origin":"","legend":"\u003cp\u003eVisualization of Training and Testing Dataset (A) Accuracy Vs Epoch (B) Loss Vs Epoch\u003c/p\u003e","description":"","filename":"7.png","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/ffba56704ce38d7d49276ec3.png"},{"id":65355174,"identity":"ccf972e4-4385-482a-8cc4-400a88569ec9","added_by":"auto","created_at":"2024-09-26 11:54:20","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1158939,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-3869444/v1/9004ac74-d91b-432f-bcb1-8fb01c4b5bba.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Applying Deep Learning Techniques for Network Traffic Classification: A Comparison Study on the NSL-KDD Dataset","fulltext":[{"header":"1 Introduction","content":"\u003cp\u003eInternet access and various forms of smart technology are increasingly widely acknowledged as necessities today. It is possible that people's beliefs and assumptions will change as a result of increased interaction among them. Every country wants to have the most modern gadgets and the best services available. This is prompting efforts in many parts of the world to create \"smart cities.\" The research undertaken by Chatterjee et al. [\u003cspan citationid=\"CR7\" class=\"CitationRef\"\u003e7\u003c/span\u003e] provides insight into how well system security and confidentiality provisions in India's proposed smart cities mesh with citizens' use of IT-enabled services. An old saying states, \"Security today is a myth.\" Culture plays a significant role in shaping how people of various backgrounds define safety. Simply put, the term \"e-communication,\" which also refers to \"electronic communication,\" covers a wide variety of situations. When people and their environments are able to have meaningful conversations, we call that \"communication.\" To put it another way, communication allows for the unhindered exchange of thoughts and information between people. These messages can be conveyed via a wide range of channels, from spoken words and body language to ciphers and facial expressions.\u003c/p\u003e \u003cp\u003eWith the advent of so many different types of Webs 2.0, global compatibility of technical standards is growing, as reported by Kar et al. [\u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e21\u003c/span\u003e]. This made it critical to set up and keep reliable lines of communication open. Example: As [\u003cspan citationid=\"CR36\" class=\"CitationRef\"\u003e36\u003c/span\u003e] demonstrates, it is difficult for individuals to fully grasp security provisions and risks due to the mashup of IT terminology and financial flow.\u003c/p\u003e \u003cp\u003eAccording to Ever et al. [\u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e15\u003c/span\u003e], artificial intelligence has come a long way in the last few decades. Animals have been shown to excel at a number of commonplace tasks where humans fall short. Networking and security are two aspects of digital technology that have issues that need fixing. The amount of information that can be transmitted in a single second has increased exponentially in recent years. We have seen the development of detection, prevention, and classification machine learning algorithms during the past two decades. The underlying goal of these developments has been to improve the approach taken to challenges in the real world. For businesses to function, communication between employees is crucial for building relationships and sharing information. Internet traffic is proportional to the number of individuals using the internet at any given moment. In this article, we have authors such as A [\u003cspan citationid=\"CR26\" class=\"CitationRef\"\u003e26\u003c/span\u003e]. The traffic generated by any given user has nothing to do with the total number of users who access a given web server. Distinguishing unusual trends in the traffic data from the norm requires statistical analysis. Due to the proliferation of digital information, the volume of network traffic has skyrocketed in the past decade. There have been efforts to make communication protocols safer and easier to use by conceiving and building them to be more user-friendly. These initiatives have been taken to improve the accessibility of existing communication technologies. The adaptability of the protocols makes them vulnerable to manipulation by cybercriminals. To paraphrase Lee and Stolfo.[\u003cspan citationid=\"CR27\" class=\"CitationRef\"\u003e27\u003c/span\u003e], \"intrusion detection\" is a crucial step in protecting systems from such assaults. Issues related to web attacks can be identified and resolved with the help of AI.\u003c/p\u003e \u003cp\u003eIdentification of potential intruders is made easier with the help of machine learning techniques such as the convolutional neural networks described by Ding and Zhai [\u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e13\u003c/span\u003e], the hybrid data mining approach described by [\u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e3\u003c/span\u003e], and the genetic algorithm with a vectorized fitness function described by [\u003cspan citationid=\"CR31\" class=\"CitationRef\"\u003e31\u003c/span\u003e]. Success is measured in part by how well a solution meets the requirements of a fitness function. A fitness score is assigned to each numerical string in genetic algorithms based on the evaluation the algorithm does. No matter how high or low your score is, it doesn't matter. It's useful for characterizing how well-suited a certain solution is. In this study, we'll take a quick look at how effectively various machine learning algorithms spot intrusion attempts and grade their effectiveness. The objective of this work is to conduct this kind of analysis.\u003c/p\u003e \u003cp\u003eThe research aims to meet a need in the intrusion detection systems sector by integrating the findings of numerous artificial intelligence (AI) and machine learning (ML) techniques for data collection (IDS). The highest quality outputs were achieved by employing the appropriate settings for each algorithm. These objectives served as the compass by which we navigated our investigation into the subject at hand. Classification challenges, whether they are binary or involve more than two classes, require extensive hypothesis formulation and evaluation utilizing both univariate and multivariate techniques to provide greater detail on the multiple attack pathways and the relevance of intrusion detection. That holds true regardless of how many distinct classes are in play. Study several different classifiers, including the K-nearest-neighbour technique, linear and quadratic support vector machine classifiers with linear kernels, and long short-term memory. We will use the k-nearest-neighbour classifier and the multi-layer perceptron to study the DoS, Probe, R2L, and U2R assaults, as well as the more common ones. Each form of assault will also have its efficacy evaluated.\u003c/p\u003e \u003cp\u003eThe study consists of an introductory section, a review of the relevant literature, and a discussion of information systems, cyber security challenges, and AI-based algorithms designed to alleviate these issues. Univariate and bivariate analysis are just two examples of the research methods covered in Section \u003cspan refid=\"Sec3\" class=\"InternalRef\"\u003e3\u003c/span\u003e's overview. Discussion of the results can be found in Section \u003cspan refid=\"Sec14\" class=\"InternalRef\"\u003e4\u003c/span\u003e, which comes right after. As we mentioned in Section \u003cspan refid=\"Sec22\" class=\"InternalRef\"\u003e5\u003c/span\u003e, we'll be talking about the study's theoretical and practical ramifications later. In Section \u003cspan refid=\"Sec22\" class=\"InternalRef\"\u003e5\u003c/span\u003e, we report the results and discuss the study's implications moving forward.\u003c/p\u003e"},{"header":"2 Related Works","content":"\u003cp\u003eModern society would crumble without the inventions and innovations made possible by technology. Due to the advent of new technologies like cordless phones, satellite TV, cloud computing, and SpaceX, the fundamental tenets upon which information systems are based have been shattered, causing a dramatic shift in their purpose. When trying to analyse and fix complex business issues, it's proven crucial to get perspectives from a wide range of areas and sources. With the proliferation of digital services, the protection of personal information has become a critical concern. Every successful company today needs a secure data storage facility and an effective data backup strategy. Any business, no matter how big or small, requires at least one employee who can assess and fully understand information technology (IT) [\u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2\u003c/span\u003e]. Information can be understood as anything that can be directly viewed in the physical environment. Items can refer to anything from a collection of numbers to a visual representation of a person's tastes and preferences. The two gentlemen of [\u003cspan citationid=\"CR8\" class=\"CitationRef\"\u003e8\u003c/span\u003e] the story could be based on a novel, or it could be inspired by many other pieces of literature. It may be purely a mental construct. Books and other written resources at a library are worth their weight in gold when it comes to gaining knowledge. The end is not in sight... There's more to come... More to come... To be continued: [\u003cspan citationid=\"CR33\" class=\"CitationRef\"\u003e33\u003c/span\u003e] many people use libraries and other book-related data sources as if they were information systems. The two authors [\u003cspan citationid=\"CR24\" class=\"CitationRef\"\u003e24\u003c/span\u003e], it is possible for IT infrastructure issues to arise, and [\u003cspan citationid=\"CR5\" class=\"CitationRef\"\u003e5\u003c/span\u003e] discuss some of the more common ones. A number of factors, including the system's quality, characteristics, retrieval methods, etc., could be to blame for these issues.\u003c/p\u003e \u003cp\u003eInformation quality and reliability [\u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e14\u003c/span\u003e], the need for users to maintain some measure of privacy and control over their data, and the services that rely on it all contribute to the difficulty of ensuring the cybersecurity of information systems. As the frequency of malicious cyber activity rises, the ability to detect breaches is becoming increasingly important. Tonge et al. [\u003cspan citationid=\"CR40\" class=\"CitationRef\"\u003e40\u003c/span\u003e] released their work in 2013. Everyone, not just those who work in IT, has a responsibility to help keep the internet a safe and trustworthy place to conduct business. Cheval There is no industry immune to the devastation that may be caused by a cyberattack today. Three devoted Muslims: [\u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e22\u003c/span\u003e] Automatic learning has progressed at the same time that cybersecurity monitoring systems have improved. According to Reshmi, the connection between Al and ML has turned possessive and intrusive.\u003c/p\u003e \u003cp\u003eMaking a decision requires hardly any time at all. Many algorithms and intrusion detection systems can be used to safeguard data locally or in the cloud. And as for [\u003cspan citationid=\"CR10\" class=\"CitationRef\"\u003e10\u003c/span\u003e], the Internet's early pattern-matching algorithms have been used to detect malicious cyber activities. The aforementioned pattern-matching job was executed using an algorithm developed by [\u003cspan citationid=\"CR43\" class=\"CitationRef\"\u003e43\u003c/span\u003e]. Therefore, the algorithms were analysed thoroughly. Yin implemented methods from the Boyer-Moore string search algorithm (BMH), the Aho-Corasick algorithm (AC-BM), and the BMH (2012). The efficacy of the model's application is dependent on the precision of the algorithm's results. The naive technique, the Knuth-Morris-Pratt algorithm, and the Rabin-Karp algorithm are all merged into one in [\u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e9\u003c/span\u003e] work on intrusion detection. The internet makes it possible to disseminate data in bite-sized chunks. There are applications in these bundles that can scan networks for issues and predict traffic flows with high precision. These records are stored in files with the. pcap extension. Having access to PCAP files is helpful because they can identify serious issues in a network that need immediate action. When PCAP files were added to the datasets, the algorithms' accuracy jumped by 16%.\u003c/p\u003e \u003cp\u003eNetwork traffic is growing exponentially as the number of people using smartphones and other connected devices rises. Since some attributes are found to be duplicated, detection takes longer. The use of IG (information gain) and gain measurement in our performance evaluation is inspired by [\u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e1\u003c/span\u003e] analysis of correlation-based feature selection algorithms. In a 2013 paper by Chae et al. proposed improved feature selection methods by weighting characteristics equally across all classes and all situations. Before the data has been cleaned and prepared, knowledge discovery cannot take place. Well-prepared data is essential for trustworthy and accurate analysis. Those lawyers' names are [\u003cspan citationid=\"CR32\" class=\"CitationRef\"\u003e32\u003c/span\u003e]. The study evaluates the efficacy of three assault detection techniques, including decision trees, random forests, and rule-based classifiers.\u003c/p\u003e \u003cp\u003eBe sure to involve Poonam and the rest of the team. To prove the efficacy of outlier detection, Kumar et al. [\u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e23\u003c/span\u003e] sought to develop a state-of-the-art model for intrusion detection capable of both outlier identification and clustering methodologies simultaneously. After laying the groundwork in [\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e], Denatious and John [\u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e11\u003c/span\u003e] describe a variety of data mining techniques. These aid in the development of trustworthy ID models and offensive tactics. Now the user can establish a protected network. The ease with which attacks can be discovered using the right optimizers and learning rate is a function of the datasets and features employed [\u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e18\u003c/span\u003e] are just an example.\u003c/p\u003e \u003cp\u003eIn order to function at maximum efficiency, optimizers are required. On the contrary, AdaBoost-based models were taken into account by [\u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e17\u003c/span\u003e]. The detection rates and overall efficacy of the logistic model are both quite high. To make sure the model hasn't been \"tweaked\" too much to fit the data, cross-validation is used. For text classification, the \"k-nearest neighbour\" (KNN) technique is used. A straightforward method of identifying the most common forms of online criminality. Experiments have demonstrated that KNN can increase model accuracy while simultaneously decreasing the false-positive rate. KNN's computational improvements make it simpler to factor in a user's prior behaviour when classifying features. For example, Liao and Vemuri [\u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e28\u003c/span\u003e] show that the kNN classifier is effective in finding hackers who have broken into a system.\u003c/p\u003e \u003cp\u003eIngre and Yadav [\u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e19\u003c/span\u003e] and Tavallaee et al. [\u003cspan citationid=\"CR38\" class=\"CitationRef\"\u003e38\u003c/span\u003e] outline the shortcomings of the original KDD dataset, which inspired the creation of the NSL KDD dataset. By and large, the BAT model created by Su et al. (2020) is a traffic anomaly detection model. A prolonged effect like this allows us to benefit from enhanced cognition and memory for a longer period of time. The data obtained by attentional processes is useful for scheduling resources in a network. Due to its adaptable structure, traffic data can be gathered in the proper context. In order to better display the data required to conceal unnecessary traits, [\u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e25\u003c/span\u003e] method is preferred. Data was reduced by 80.4%, and training time was cut by 40%. The duration of the examinations was reduced by 70%. The NSL KDD dataset was largely influenced by the work of [\u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e19\u003c/span\u003e] and Tavallaee et al. [\u003cspan citationid=\"CR38\" class=\"CitationRef\"\u003e38\u003c/span\u003e]. In conclusion, [\u003cspan citationid=\"CR37\" class=\"CitationRef\"\u003e37\u003c/span\u003e] BAT model is a traffic anomaly detection model. A prolonged effect like this allows us to benefit from enhanced cognition and memory for a longer period of time. The data obtained by attentional processes is useful for scheduling resources in a network. Due to its adaptable structure, traffic data can be gathered in the proper context. In order to better display the data required to conceal unnecessary traits, [\u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e25\u003c/span\u003e] method is preferred. Data was reduced by 80.4%, and training time was cut by 40%. The duration of the examinations was reduced by 70%. Compared to the control CNN and RNN models, the BAT model fared better. The need for a more comprehensive database is discussed further below. As a result, classifiers were created to sort the data into meaningful groups. The working accuracy of the model improved while using a large enough dataset. The researchers didn't concentrate on a specific population to keep the study's costs in check. More frequent data is required to increase the accuracy of the model. This kind of thinking might be categorized as prejudice. After getting rid of all the duplicates in the original dataset, we were able to update NSL-KDD. Careful consideration was given to including information from all potential difficulties in the new collection. Proportionally inverse to how much of the old KDD data set was incorporated into the new records. In order to improve the accuracy of the classification models, it is recommended to apply multiple models to the dataset. By combining data from multiple studies into one cohesive collection, we may more confidently draw conclusions.\u003c/p\u003e"},{"header":"3 Methods and Materials","content":"\u003cdiv id=\"Sec4\" class=\"Section2\"\u003e \u003ch2\u003e3.1 Dataset\u003c/h2\u003e \u003cp\u003eThis experiment makes use of the NSL-KDD benchmark dataset rather than the original KDD Cup 99 dataset because the former provides a better baseline for determining the efficacy of the model that we developed. This is because the latter resolved some issues that had been extensively discussed in the past. Even though this dataset still has the problems we talked about earlier, academics who study intrusion detection use it often, so we think it is real.\u003c/p\u003e \u003cp\u003eIn addition to regular flow patterns, the collection also contains a wide variety of unusual occurrences. There are five distinct types, including denial of service attacks, regular traffic attacks, U2R attacks, R2L attacks, probing assaults, and regular attacks. Their breakdown is shown in Table I. DoS attacks, regular traffic attacks, U2R attacks, R2L attacks, and probing assaults are all part of it.\u003c/p\u003e \u003cp\u003eThere are 41 features included in each record of the original NSL-KDD dataset; however, not all of these features can be accurately represented while being trained. The data must be preprocessed, and the symbolic characteristics of the protocol type, service, and flag must be extended using 1-N encoding. Lastly, the flag's symbolic characteristics have to be encoded. The processed data yields a total of 122 features, which are comprised of three protocol types, seventy services, and eleven flags. These features are extracted from the data. The NSL-KDD dataset will be normalized to the interval [0, 1] after the following step, which is to perform a max-mix operation on it.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab1\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003ebreakdown of five distinct types of attacks\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colspan=\"2\" nameend=\"c2\" namest=\"c1\"\u003e \u003cp\u003eCategory\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eTraining set\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eTest set\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\" morerows=\"3\" rowspan=\"4\"\u003e \u003cp\u003e\u003cb\u003eAttacks\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e\u003cb\u003eDos\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e45927\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e7458\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e\u003cb\u003eU2R\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e52\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e67\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e\u003cb\u003eR2L\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e995\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e2887\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e\u003cb\u003eProbe\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e11656\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e2421\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colspan=\"2\" nameend=\"c2\" namest=\"c1\"\u003e \u003cp\u003e\u003cb\u003eNormal\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e67343\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e9711\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colspan=\"2\" nameend=\"c2\" namest=\"c1\"\u003e \u003cp\u003e\u003cb\u003eTotal\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e125973\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e22544\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eAccording to Dhanabal and Shantharajah [\u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e12\u003c/span\u003e], the primary forms of multi-class attacks can be broken down into four categories:\u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003eDenial-of-service, abbreviated as DOS, refers to an offensive strategy that interferes with service. Attacks of this sort have the potential to bring a complete halt to all modes of transportation. Because this is the case, no data will be transmitted to the network. For instance, the availability of things may not always be up to date during huge sales events at Amazon, Flipkart, or any other e-commerce company. As a result of this, customers may try to check out with items that other customers have already purchased. DOS assaults comprise a wide variety of methods, such as mail bombs and Neptune attacks.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eAn R2L attack comes from a remote computer and seeks to acquire illegal access through the user. This type of attack is also known as a man-in-the-middle assault. Being Satan, being a warez master, or attempting to guess the CVVs of credit and debit cards in order to access online accounts are all examples of activities that fall under this category.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eAn attempt to gain full control of a network, as well as all of the information contained inside it, is referred to as a \"User-to-Root (U2R) attack.\" As the name of this type of attack suggests, the objective is to establish oneself as the only primary user so that information can be exploited commercially. There are exploits such as buffer overflow, Perl, SQL attacks, and others, to name a few examples.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eBoth overt actions of surveillance and covert inquiries might be included in the process of probing. This kind of assault is carried out with the intention of gleaning as much information and data as possible from protected networks. The information may include a person's name and gender in addition to their financial details and other sensitive data such as passwords, portsweeps, saints, and so on.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec5\" class=\"Section2\"\u003e \u003ch2\u003e3.2 Data Pre-Processing\u003c/h2\u003e \u003cp\u003eIt is necessary to perform preprocessing on the data before building a model using deep learning. When constructing a deep learning project, it is not a given that we will locate data that is both clean and well-formatted in every instance. Because of this, it is essential to thoroughly clean and format the data before carrying out any operation on it. The process of changing raw data into a format that can be utilized by an algorithm for machine learning or deep learning is referred to as \"data preparation,\" and it is the first step and, perhaps, the most critical stage in the development of a model. It's a great idea to use game-changing technologies like AI and DL to make better decisions and help companies grow, but these benefits won't be realized unless the right data processing methods are also put in place.\u003c/p\u003e \u003cp\u003eMany of the algorithms have difficulty functioning properly after categorical data has been included in a machine learning or deep learning model. Both the input and output variables of the categorical data need to be converted into their numerical equivalents. If you are involved in any kind of data science, you have most likely come across the term \"one-hot encoding.\" Sklearn's definition is \"to encode categorical integer features using a one-hot technique.\" To be more specific, it means \"to encode categorical integer features using a one-hot technique.\"\u003c/p\u003e \u003cp\u003eThe same thing happens with deep learning and other types of machine learning algorithms due to the fact that a machine can only comprehend numbers and cannot interpret the text that begins with. One-hot encoding is a crucial step in the process of preparing the categorical data variables to be submitted to machine learning and deep learning methods, which both have the potential to improve the accuracy of a model's predictions and classifications. This potential improvement is made possible by the use of techniques from the fields of machine learning and deep learning. To ensure that machine learning models work properly, categorical data must be preprocessed using a single hot encoding. Then, a unique binary feature for each possible category is made, and the value 1 is given to the feature of each sample that corresponds to the category it came from.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec6\" class=\"Section2\"\u003e \u003ch2\u003e3.3 Feature Selection\u003c/h2\u003e \u003cp\u003eFor the most accurate results, there was an emphasis placed on feature selection. Models that have been trained on relevant characteristics perform the best when it comes to classifying test sets. The following table presents the findings obtained by categorizing data according to four different approaches:\u003c/p\u003e \u003cp\u003eThe Chi-Square test was used to choose the features for the binary classification. The following are the steps that were taken after that:\u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003eFirst, one needs to make the hypothesis more specific. Since there is no correlation between the two variables, HO is correct. The alternative hypothesis states that the two variables could be interdependent on one another. This possibility exists as well (Hl).\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eSecond Using the TCP protocol type, separate the samples that resulted in an intrusion into a separate table from the samples that did not result in an intrusion.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eThird, projections were constructed by analysing past information and data. Chi-square statistics were utilized to establish the top 20 factors that were responsible for the attacks after it was found that there was a substantial association between the two.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003cp\u003e \u003cb\u003eFig .1\u003c/b\u003e Feature selection of the whole dataset\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec7\" class=\"Section2\"\u003e \u003ch2\u003e3.4 Data Standardization\u003c/h2\u003e \u003cp\u003eNormalization of the dataset Over-fitting and missing values are eliminated when the dataset is normalized. Because of the uniformity brought about by normalization, any kind of wrongdoing can be readily prevented in the future. If you want to normalize certain numbers that change over time, you can use a scale from 0 to 1 as your starting point. Moreover, normalization aids in avoiding discrepancies when giving weights to the parameters. Reducing the number of dimensions used to describe something is called \"feature reduction.\" In Ingre, Yadav, and Soni, correlation feature selection was utilized (2017). It was found that the binary class classification generated significantly more output than the five attack categories.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec8\" class=\"Section2\"\u003e \u003ch2\u003e3.5 Evaluation Metrics\u003c/h2\u003e \u003cdiv id=\"Sec9\" class=\"Section3\"\u003e \u003ch2\u003e3.5.1 F1 Score\u003c/h2\u003e \u003cp\u003eThe F1 score is less well-known than the P and R scores. It is calculated by harmonically averaging P and R scores. Zero indicates poor performance on both precision and recall. If they get a 1, they did well on both.\u003cdiv id=\"Equ1\" class=\"Equation\"\u003e\u003cdiv format=\"TEX\" class=\"mathdisplay\" id=\"FileID_Equ1\" name=\"EquationSource\"\u003e\n$$\\varvec{F}1 \\varvec{S}\\varvec{c}\\varvec{o}\\varvec{r}\\varvec{e}=\\frac{2\\varvec{T}\\varvec{P}}{(2\\varvec{T}\\varvec{P}+\\varvec{F}\\varvec{P}+\\varvec{F}\\varvec{N}\\varvec{N})}$$\u003c/div\u003e\u003cdiv class=\"EquationNumber\"\u003e1\u003c/div\u003e\u003c/div\u003e\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec10\" class=\"Section3\"\u003e \u003ch2\u003e3.5.2 Accuracy\u003c/h2\u003e \u003cp\u003eThe precision of our model can be thought of as the fraction of total predictions that turn out to be accurate. To do this, first, tally up the number of accurate positive (TP) and negative (TN) projections, and then divide that figure by the sum of all forecasts made (including accurate and inaccurate ones) (FP, FN).\u003cdiv id=\"Equ2\" class=\"Equation\"\u003e\u003cdiv format=\"TEX\" class=\"mathdisplay\" id=\"FileID_Equ2\" name=\"EquationSource\"\u003e\n$$\\varvec{A}\\varvec{c}\\varvec{c}\\varvec{u}\\varvec{a}\\varvec{r}\\varvec{c}\\varvec{y}=\\frac{(\\varvec{T}\\varvec{P}+\\varvec{T}\\varvec{N})}{(\\varvec{T}\\varvec{P}+\\varvec{T}\\varvec{N}+\\varvec{F}\\varvec{P}+\\varvec{F}\\varvec{N})}$$\u003c/div\u003e\u003cdiv class=\"EquationNumber\"\u003e2\u003c/div\u003e\u003c/div\u003e\u003c/p\u003e \u003cp\u003ePrecision ranges from zero to one. Both extremes\u0026mdash;perfect and completely wrong predictions\u0026mdash;are possible. Example: Our model won't make mistakes if it can forecast everything (positive or negative). Since the numerator and denominator are equal, the precision is 1. If our system constantly makes incorrect predictions, the sum of true positives and negatives and the difference between zero and a positive number must always be zero.\u003c/p\u003e \u003cp\u003eInverting labels can improve prediction accuracy if it drops below 0.5. Technically, accuracy is 0.5\u0026ndash;1%. However, data bias makes accuracy a poor statistic. When positive and negative labels are far apart, accuracy alone might be misleading. Consider that 95 of 100 samples are Class 0, while 5 are Class 1. A \"dummy\" model that predicts Class 0 with 95% accuracy must be effective. Because only Class 0 is predictable. Its unreliable outcomes make it impossible to evaluate the model's efficacy. If we only measured this model's correctness, stakeholders and consumers would receive an inefficient and unreliable service.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec11\" class=\"Section3\"\u003e \u003ch2\u003e3.5.3 Precision\u003c/h2\u003e \u003cp\u003eData scientists often get around problems with accuracy by using precision, recall, and specificity in their analysis. Looking at the accuracy, one can determine what fraction of optimistic predictions came true. To calculate the accuracy rate, take the total number of positive predictions and divide it by the percentage of those forecasts that turned out to be correct (TP, FP).\u003cdiv id=\"Equ3\" class=\"Equation\"\u003e\u003cdiv format=\"TEX\" class=\"mathdisplay\" id=\"FileID_Equ3\" name=\"EquationSource\"\u003e\n$$\\varvec{P}\\varvec{r}\\varvec{e}\\varvec{c}\\varvec{i}\\varvec{s}\\varvec{i}\\varvec{o}\\varvec{n}=\\frac{\\varvec{T}\\varvec{P}}{(\\varvec{T}\\varvec{P}+\\varvec{F}\\varvec{P})}$$\u003c/div\u003e\u003cdiv class=\"EquationNumber\"\u003e3\u003c/div\u003e\u003c/div\u003e\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec12\" class=\"Section3\"\u003e \u003ch2\u003e3.5.4 Recall\u003c/h2\u003e \u003cp\u003eRecall, much like accuracy, determines how many of the questions asked were answered correctly. In order to arrive at this result, we divide the total number of samples that tested positive by the overall number of samples that tested positive (TP, FN).\u003cdiv id=\"Equa\" class=\"Equation\"\u003e\u003cdiv format=\"TEX\" class=\"mathdisplay\" id=\"FileID_Equa\" name=\"EquationSource\"\u003e\n$$\\varvec{R}\\varvec{e}\\varvec{c}\\varvec{a}\\varvec{l}\\varvec{l}=\\frac{\\varvec{T}\\varvec{P}}{(\\varvec{T}\\varvec{P}+\\varvec{F}\\varvec{N})} \\left(4\\right)$$\u003c/div\u003e\u003c/div\u003e\u003c/p\u003e \u003c/div\u003e \u003c/div\u003e \u003cdiv id=\"Sec13\" class=\"Section2\"\u003e \u003ch2\u003e3.6 Study Model\u003c/h2\u003e \u003cp\u003eThe suggested algorithm's overall layout is depicted in Fig.\u0026nbsp;\u003cspan refid=\"Fig1\" class=\"InternalRef\"\u003e2\u003c/span\u003e, which may be seen here. The goal of these model-based investigations was to make the NSL-KDD dataset easier to read and easier to put into groups.\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003c/div\u003e"},{"header":"4 Experiment Result","content":"\u003cdiv id=\"Sec15\" class=\"Section2\"\u003e \u003ch2\u003e4.1 Binary Classification\u003c/h2\u003e \u003cp\u003eWithin the framework of the binary categorization system, the only two outcomes that are conceivable are \"normal\" and \"abnormal.\" A score of 0 indicated that the labels were abnormal, while a value of 1 indicated that they were normal. We employed one-hot coding on attack labels so that we could more accurately map the attacks and categorize them. To successfully decode the information that is being provided to it, one-hot encoding is a necessary step. It does this by converting information into a form that can be read by machines called binary.\u003c/p\u003e \u003cp\u003eTo ascertain the level of association that existed between the features of the binary class dataset, the Pearson correlation test was carried out. By utilizing Pearson's correlation, we can gain an understanding of the connections that exist between the various continuous variables. Yes (l) and no are the only two choices that can be made in response to the intrusion question (0). As a result, a new dataset was selected for further examination after it was determined which attributes had a correlation of more than 0.5 and after the encoded, one-hot-encoded, and original attack label attributes were merged.\u003c/p\u003e \u003cdiv id=\"Sec16\" class=\"Section3\"\u003e \u003ch2\u003e4.1.1 Linear Kernel Support Vector Machine Classifier for Linear and Quadratic Data\u003c/h2\u003e \u003cp\u003eIn this section, the outcomes of employing a Linear Kernel Support Vector Machine (L-SVM) classifier on the linear and quadratic data within the NSL-KDD dataset are presented. The L-SVM classifier is renowned for its efficacy in handling linearly separable data, as it employs a linear decision boundary to distinguish between classes. Table\u0026nbsp;\u003cspan refid=\"Tab2\" class=\"InternalRef\"\u003e2\u003c/span\u003e presents the classification report pertaining to the L-SVM classifier. The metrics of precision, recall, and F1-score are presented for both the \"abnormal\" and \"normal\" classes. The L-SVM classifier exhibits excellent performance, with precision scores of 0.98 and 0.97 for the \"abnormal\" and \"normal\" classes, respectively. Additionally, it demonstrates robust recall scores of 0.97 and 0.98, leading to a well-balanced performance across all categories. The L-SVM classifier achieves an F1-score of 0.97 for the \"abnormal\" class and 0.98 for the \"normal\" class.\u003c/p\u003e \u003cp\u003eIn addition to the L-SVM classifier, we also investigated the Quadratic Support Vector Machine (Q-SVM) classifier, which employs a quadratic decision boundary to effectively handle intricate and non-linearly separable datasets. The classification report for the Q-SVM classifier is presented in Table\u0026nbsp;\u003cspan refid=\"Tab3\" class=\"InternalRef\"\u003e3\u003c/span\u003e. It is worth mentioning that the Q-SVM classifier demonstrates a remarkable precision of 1.00 for the \"abnormal\" class, signifying that all positive predictions are correct. The precision achieved by the \"normal\" class is 0.95. The Q-SVM classifier exhibits high recall scores of 0.94 for the \"abnormal\" class and 1.00 for the \"normal\" class, indicating its strong performance in correctly identifying instances belonging to these classes. The F1-scores obtained for the \"abnormal\" and \"normal\" classes are 0.96 and 0.97, respectively. The results of this study demonstrate the efficacy of both the Linear Support Vector Machine (L-SVM) and Quadratic Support Vector Machine (Q-SVM) classifiers in accurately categorizing the linear and quadratic data within the NSL-KDD dataset. The L-SVM classifier exhibits superior performance in accurately representing the attributes of linearly separable data, whereas the Q-SVM classifier showcases its proficiency in addressing intricate, non-linear patterns. The efficacy of the linear support vector machine (L-SVM) classifier in the context of network security is evident, as it demonstrates promising outcomes for intrusion detection. The achieved precision for both the \"abnormal\" and \"normal\" classes is high, suggesting a low occurrence of false positives. This implies that the classifier demonstrates a high level of accuracy in correctly predicting instances as either \"abnormal\" or \"normal\" in the majority of cases.\u003c/p\u003e \u003cp\u003eThe recall scores exhibit significance, particularly in relation to the \"normal\" class. This finding suggests that the L-SVM classifier successfully detects instances of normal network traffic, thereby reducing the occurrence of false negatives. A high recall score pertaining to the \"abnormal\" class signifies that the classifier is capable of identifying a significant proportion of intrusions. In general, the F1-scores demonstrate a favorable equilibrium between precision and recall for both categories. This indicates that the L-SVM classifier effectively discriminates between regular network traffic and anomalous activity, thereby facilitating the identification of potential intrusions. The utilization of the quadratic support vector machine (Q-SVM) classifier has been shown to exhibit strong and reliable performance in the context of network security applications. The exceptional precision score achieved by the Q-SVM classifier for the \"abnormal\" class indicates its proficiency in accurately detecting instances of abnormal behavior. The detection of potential intrusions and the maintenance of network security are of utmost importance.\u003c/p\u003e \u003cp\u003eThe Q-SVM classifier demonstrates effective recognition of legitimate network traffic, resulting in a reduced false positive rate, as indicated by the high precision score for the \"normal\" class. The exemplary recall score associated with the \"normal\" class underscores its efficacy in accurately identifying all instances of normal behavior, thereby minimizing the risk of misclassifying legitimate traffic as abnormal. The F1-scores for both classes exhibit robust performance, indicating a harmonious trade-off between precision and recall. This suggests that the Q-SVM classifier has the ability to accurately classify instances in both the \"abnormal\" and \"normal\" classes, thereby enhancing the overall efficacy of intrusion detection in a network security setting.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab2\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eLiner Support Vector Machine Classification Report\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eL-SVM\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eprecision\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003erecall\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003ef1-score\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eabnormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003enormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab3\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eQuadratic Support Vector Machine Classification Report\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eQ-SVM\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eprecision\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003erecall\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003ef1-score\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eabnormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e1.00\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.94\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.96\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003enormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.95\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e1.00\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec17\" class=\"Section3\"\u003e \u003ch2\u003e4.1.2 Binary Classification using K-Nearest-Neighbor Classifier\u003c/h2\u003e \u003cp\u003eIn this section, the outcomes of utilizing a K-Nearest Neighbor (KNN) classifier for the purpose of conducting binary classification on the NSL-KDD dataset are presented. The K-nearest neighbors (KNN) algorithm is a non-parametric approach that assigns class membership to a given sample by considering its proximity to the nearest neighbors in the feature space. The classification report for the KNN classifier is presented in Table\u0026nbsp;\u003cspan refid=\"Tab4\" class=\"InternalRef\"\u003e4\u003c/span\u003e. The metrics of precision, recall, and F1-score are presented for both the \"abnormal\" and \"normal\" classes. The K-nearest neighbors (KNN) classifier demonstrates a notable level of precision for both classes, exhibiting a precision rate of 0.98 for the \"abnormal\" class and 0.97 for the \"normal\" class. This observation suggests that the KNN classifier exhibits a low rate of false positives, thereby reducing the occurrence of misclassifying normal instances as abnormal, and vice versa.\u003c/p\u003e \u003cp\u003eThe recall scores are particularly notable, particularly in the \"normal\" class, where the KNN classifier achieves a flawless recall score of 1.00. This suggests that the classifier successfully detects and categorizes all instances of typical network activity, thereby preventing legitimate traffic from being mistakenly classified as anomalous. The K-nearest neighbors (KNN) classifier demonstrates a recall score of 0.98 for the \"abnormal\" category, signifying its proficiency in accurately detecting a substantial number of abnormal instances. The F1-scores for both classes demonstrate an equilibrium between precision and recall, yielding an overall F1-score of 0.97 for the \"abnormal\" class and 0.98 for the \"normal\" class. This study showcases the efficacy of the K-nearest neighbors (KNN) classifier in accurately categorizing instances and discerning between normal and abnormal network behavior.\u003c/p\u003e \u003cp\u003eThe findings of the binary classification utilizing the KNN classifier highlight its efficacy as a dependable approach for detecting intrusions in network security. The commendable precision and recall scores exhibited by the system highlight its capacity to effectively discern between normal and abnormal network traffic, thereby enhancing the overall efficacy of intrusion detection systems. The K-Nearest Neighbor (KNN) classifier exhibits robust performance in the context of intrusion detection from a network security standpoint. The precision scores for both the \"abnormal\" and \"normal\" classes demonstrate a minimal occurrence of false positives. This implies that the accuracy of the KNN classifier in predicting an instance as either \"abnormal\" or \"normal\" is high in the majority of cases.\u003c/p\u003e \u003cp\u003eThe recall scores exhibit noteworthy performance, as evidenced by a perfect recall score of 1.00 for the \"normal\" class. This suggests that the K-nearest neighbors (KNN) classifier successfully captures all instances of normal network traffic, thereby reducing the occurrence of false negatives. This showcases a proficient capacity to discern authentic network behavior, thereby ensuring that regular traffic is not erroneously categorized as anomalous. The K-nearest neighbors (KNN) classifier demonstrates a recall score of 0.98 for the \"abnormal\" class, suggesting its efficacy in accurately detecting a substantial portion of abnormal instances. The detection of potential intrusions and the maintenance of network security are of utmost importance. The F1-scores for both classes demonstrate a harmonious trade-off between precision and recall, suggesting a robust overall performance of the KNN classifier in effectively categorizing instances and discerning between normal and abnormal network behavior.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab4\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eKNN Classification Report\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eKNN\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eprecision\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003erecall\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003ef1-score\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eabnormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003enormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e1.00\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.98\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec18\" class=\"Section3\"\u003e \u003ch2\u003e4.1.3 Binary Classification using Long Short-Term Memory Classifier\u003c/h2\u003e \u003cp\u003eThis section presents the outcomes of employing a Long Short-Term Memory (LSTM) classifier for the purpose of binary classification on the NSL-KDD dataset. The Long Short-Term Memory (LSTM) is a specific variant of the recurrent neural network (RNN) architecture, which has demonstrated its efficacy in effectively capturing sequential patterns and dependencies within datasets. Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e presents the evaluation metrics pertaining to the LSTM model. The recall score, F1-score, and precision score are reported in the study. The LSTM classifier exhibits a recall score of 0.989, indicating its proficiency in accurately identifying a significant proportion of true positive instances within the dataset. Accurate identification and detection of intrusions is of utmost importance in this context.\u003c/p\u003e \u003cp\u003eThe LSTM classifier achieved an F1-score of 0.976, which represents a harmonious trade-off between precision and recall. This implies a robust performance in terms of accurately classifying instances, effectively identifying true positive cases, and minimizing both false positives and false negatives. The LSTM classifier demonstrates a low false positive rate, as evidenced by its precision score of 0.963. The system effectively distinguishes positive instances and reduces the occurrence of misclassifying normal instances as abnormal. Ensuring the reliability of the intrusion detection system and reducing the occurrence of false alarms are crucial factors to consider. The efficacy of the LSTM model in binary classification for intrusion detection on the NSL-KDD dataset is demonstrated by the evaluation metrics presented in Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e. The high recall score, F1-score, and precision score of the model indicate its proficiency in accurately categorizing instances and efficiently discerning between normal and abnormal network behavior. The utilization of the LSTM classifier in network security applications is highly advantageous due to its ability to effectively capture sequential patterns and dependencies. This makes it a valuable tool, particularly in scenarios where real-time detection of intrusions is of utmost importance.\u003c/p\u003e \u003cp\u003eThe performance of the LSTM classifier is deemed exceptional in terms of network security, as evidenced by the evaluation metrics presented in Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e. The aforementioned metrics offer valuable insights into the classifier's capacity to accurately classify instances and its overall efficacy in the field of intrusion detection. The recall score, which measures the proportion of true positive instances correctly identified by a network security system, is a crucial metric with a value of 0.989. The high sensitivity of the LSTM classifier is evident in its ability to accurately identify true positive instances, which refer to actual intrusions in the given context. The LSTM classifier demonstrates a recall score of 0.989, indicating its effective ability to detect a substantial number of intrusions within the NSL-KDD dataset, thereby minimizing the occurrence of false negatives. The detection and notification of potential security breaches is of utmost importance.\u003c/p\u003e \u003cp\u003eThe F1-score, which has a value of 0.976, indicates a well-balanced performance in terms of both precision and recall. The findings suggest that the LSTM classifier effectively balances the task of accurately detecting intrusions while simultaneously minimizing the occurrence of both false positives and false negatives. The high F1-score demonstrates the classifier's efficacy in delivering dependable intrusion detection capabilities for network security applications. The LSTM classifier's precision score of 0.963 highlights its proficiency in minimizing the occurrence of false positives. The data suggests that the classifier demonstrates an accuracy rate of approximately 96.3% in correctly identifying instances as intrusions. The precision score serves as a measure of the classifier's efficacy in minimizing false positives and mitigating unnecessary disruptions resulting from misclassifying regular instances as intrusions.\u003c/p\u003e \u003cp\u003eThe evaluation metrics presented in Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e demonstrate the robust performance of the LSTM model in the context of network security applications. The combined evaluation metrics of high recall score, F1-score, and precision score collectively demonstrate the LSTM classifier's efficacy in accurately identifying and categorizing intrusions, thereby serving as a valuable instrument for augmenting network security.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab5\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 5\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eEvaluation Metric of the LSTM model\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"2\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eRecall Score\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.989\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eF-1 Score\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.976\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003ePrecision Score\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.963\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003cp\u003eThe operational characteristic curve (ROC) serves as a valuable graphical depiction of the diagnostic accuracy of a binary classifier system within the realm of network security. The performance of the classifier system is demonstrated by the ROC curve through the manipulation of the discrimination threshold. The ROC analysis was first introduced in 1941 specifically for military radar sensors. It offers a systematic approach to choosing the most effective models and discarding less effective ones, irrespective of the cost context or class distribution. As a result, it improves the decision-making process. The research incorporates comprehensive analyses of these methodologies. In the realm of network security, there exists a logical and straightforward connection between ROC analysis and cost-benefit analysis of diagnostic options. The ROC curve in Fig.\u0026nbsp;6 illustrates the performance of the LSTM model in effectively detecting and classifying intrusions.\u003c/p\u003e \u003c/div\u003e \u003c/div\u003e \u003cdiv id=\"Sec19\" class=\"Section2\"\u003e \u003ch2\u003e4.2 Multi-Class Classification\u003c/h2\u003e \u003cp\u003eThe network security framework encompasses a range of attack types, such as Denial of Service (DoS), Probe, Remote-to-Local (R2L), User-to-Root (U2R), and general attacks. In order to facilitate the analysis of the data, we utilized both one-hot encoding and label encoding methodologies. These techniques were employed to convert the dataset into a numerical format, wherein multiple labels were assigned to represent the various categories of assaults. The application of Pearson correlation allowed us to identify the most robust associations among the attributes present in the multi-class dataset. The utilization of Pearson's correlation coefficient facilitated the assessment of the degree of association between variables that are measured on a continuous scale. By employing this methodology, we were able to exploit the dual advantages of the multi-class nature of the data, encompassing multiple attack types, as well as the numerical attributes associated with it. Through the integration of the encoded, one-hot-encoded, and original attack label properties, we successfully identified the variables exhibiting a correlation exceeding 0.5. The aforementioned selection process yielded a more refined dataset that can now be subjected to further scrutiny.\u003c/p\u003e \u003cdiv id=\"Sec20\" class=\"Section3\"\u003e \u003ch2\u003e4.2.1 K-Nearest-Neighbor Classifier\u003c/h2\u003e \u003cp\u003eThis section focuses on the utilization of the K-Nearest Neighbor (kNN) classifier for multi-class classification on the NSL-KDD dataset. The k-nearest neighbors (kNN) algorithm is widely utilized in the field of machine learning for the purpose of classifying instances. This algorithm determines the class of an instance by considering its proximity to labeled examples within the feature space. The multi-class classification report for the kNN classifier is presented in Table\u0026nbsp;\u003cspan refid=\"Tab6\" class=\"InternalRef\"\u003e6\u003c/span\u003e. The metrics of precision, recall, and F1-score are presented for each class, namely Dos, Probe, R2L, U2R, and Normal. The precision score quantifies the ratio of accurately predicted instances for a particular class, whereas the recall score evaluates the ratio of correctly classified actual instances. The F1-score can be defined as the mathematical average of precision and recall, which offers a well-balanced evaluation of classification effectiveness.\u003c/p\u003e \u003cp\u003eThe k-nearest neighbors (kNN) classifier exhibits a notable level of precision across the majority of classes. The precision scores obtained for the different attack types are as follows: 0.96 for Denial of Service (DoS), 0.99 for Probing, 0.94 for Remote to Local (R2L), 0.50 for User to Root (U2R), and 0.94 for Normal. The aforementioned scores serve as a measure of the kNN classifier's proficiency in accurately categorizing instances within each respective class. Likewise, the recall scores exhibit a high level of performance, as evidenced by the values of 0.97 for Denial of Service (DoS), 0.99 for Probing, 0.93 for Remote to Local (R2L), 0.87 for User to Root (U2R), and 0.93 for Normal. The obtained scores indicate that the kNN classifier successfully captures a substantial proportion of instances for every class. The classifier's performance is further supported by the F1-scores, which demonstrate values of 0.95 for the Dos category, 0.99 for Probe, 0.93 for R2L, 0.35 for U2R, and 0.97 for Normal. The observed scores exhibit a commendable equilibrium between precision and recall, which suggests that the classifier possesses the ability to accurately classify instances across various classes.In the context of multi-class classification on the NSL-KDD dataset, the kNN classifier demonstrates favorable performance. The effectiveness of the model in distinguishing between various types of network traffic and accurately classifying instances is demonstrated by its high precision, recall, and F1-scores for each class.\u003c/p\u003e \u003cp\u003eThe performance of the k-nearest neighbors (kNN) classifier in the context of multi-class classification offers valuable insights when considering network security. The presented table displays the metrics of precision, recall, and F1-score for each class, specifically Dos, Probe, R2L, U2R, and Normal. These metrics aid in evaluating the efficacy of the classifier in accurately categorizing instances and offer a comprehensive comprehension of its performance in network security applications.\u003c/p\u003e \u003cp\u003eThe precision scores represent the ratio of accurately predicted instances for each class. The kNN classifier demonstrates strong performance in accurately identifying instances within each class, as evidenced by high precision scores. Specifically, Dos achieves a precision score of 0.96, Probe achieves 0.99, R2L achieves 0.94, U2R achieves 0.50, and Normal achieves 0.94. The minimization of misclassification of instances is of utmost importance in the context of network security, as it enhances the reliability of intrusion detection. The recall scores serve as an indicator of the classifier's capacity to accurately identify and include true instances of every class. The k-nearest neighbors (kNN) classifier exhibits high recall scores, specifically achieving values of 0.97 for the Denial of Service (Dos) category, 0.99 for Probe, 0.93 for Remote to Local (R2L), 0.87 for User to Root (U2R), and 0.93 for Normal. The obtained scores demonstrate the classifier's efficacy in accurately detecting and classifying various types of network traffic by effectively identifying a substantial proportion of instances within each class.\u003c/p\u003e \u003cp\u003eThe F1-scores offer a comprehensive evaluation of the classifier's effectiveness by taking into account both precision and recall. The k-nearest neighbors (kNN) classifier demonstrates notable performance in terms of F1-scores, exhibiting values of 0.95 for Denial of Service (Dos), 0.99 for Probe, 0.93 for Remote to Local (R2L), 0.35 for User to Root (U2R), and 0.97 for Normal. The observed scores suggest a favorable equilibrium between precision and recall, which signifies the classifier's efficacy in correctly categorizing instances while minimizing the occurrence of both false positives and false negatives. The findings presented in Table\u0026nbsp;\u003cspan refid=\"Tab6\" class=\"InternalRef\"\u003e6\u003c/span\u003e indicate that the k-nearest neighbors (kNN) classifier exhibits strong performance in the context of multi-class classification for network security applications. The high precision, recall, and F1-scores exhibited by the model across various classes highlight its ability to accurately classify instances and make a significant contribution to the effectiveness of intrusion detection.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab6\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 6\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003ekNN Multi-Class Classification Report\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"5\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e\u0026nbsp;\u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eprecision\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003erecall\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003ef1-score\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c5\"\u003e \u003cp\u003esupport\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eDos\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.96\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.95\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003e11484\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eProbe\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.99\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.99\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.99\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003e2947\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eR2L\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.94\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.93\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.93\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003e274\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eU2R\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.50\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.87\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.35\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003e15\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eNormal\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e0.94\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003e0.93\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003e0.97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003e16774\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec21\" class=\"Section3\"\u003e \u003ch2\u003e4.2.2 Multi-Layer Perceptron Classifier\u003c/h2\u003e \u003cp\u003eThe effective implementation of deep learning in the field of network security is largely dependent on the application of neural networks. Neural networks are comprised of interconnected neurons, which serve as pivotal components in the processing of information and the formulation of decisions. Neural networks in the field of network security serve as algorithms for identifying and resolving problems, enabling accurate categorization of network traffic. The utilization of a linear hyper-plane enables the establishment of a basic two-classification system. However, the incorporation of hidden layers becomes imperative when confronted with diverse network behaviors. The Adam optimization algorithm was utilized in our study to determine the optimal configuration for the sequential model. In order to enhance the process of acquiring knowledge, we integrated a softmax activation function and employed a loss function that is derived from categorical cross-entropy. The model underwent training for a total of one hundred epochs in order to improve its precision. After taking into account all relevant factors, the model's overall accuracy was determined to be 99.23%. The visualization of the relationship between accuracy and decay over time is depicted in Fig.\u0026nbsp;8.\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003c/div\u003e \u003c/div\u003e"},{"header":"5 Conclusion","content":"\u003cp\u003eThe present study investigates the utilization of machine learning methodologies within the domain of network security, with a specific emphasis on the categorization of network traffic utilizing the NSL-KDD dataset. The results underscore the efficacy of different classifiers in the context of intrusion detection and network security. The study revealed that the Linear Support Vector Machine (SVM) classifier exhibited notable precision and recall scores, suggesting its proficiency in accurately categorizing instances of abnormal and normal network behavior. In a similar vein, the Quadratic Support Vector Machine (SVM) classifier exhibited exceptional precision in identifying abnormal instances and achieved flawless recall in detecting normal instances. This characteristic renders it a highly valuable instrument for capturing diverse forms of network traffic.\u003c/p\u003e \u003cp\u003eThe assessment of the K-Nearest Neighbor (kNN) classifier demonstrated high precision and recall scores across various classes, highlighting its potential for effectively classifying multiple categories in intrusion detection and network security contexts. In addition, the Long Short-Term Memory (LSTM) classifier demonstrated exceptional recall and F1-scores due to its capacity to effectively capture sequential patterns and dependencies. This characteristic renders it a valuable resource for effectively identifying intrusions within network traffic. Preprocessing techniques, such as one-hot encoding and normalization, have been instrumental in improving the efficacy of machine learning models in the domain of network security. Moreover, the inclusion of feature selection was found to be crucial in attaining optimal outcomes in classification.\u003c/p\u003e \u003cp\u003eIn summary, this study showcases the capabilities of machine learning methodologies in the classification of network traffic and identification of intrusions, thereby playing a crucial role in upholding network security. The efficacy of different classifiers, such as Linear SVM, Quadratic SVM, kNN, and LSTM, was demonstrated in multiple domains of network security. By utilizing these models, organizations can augment their capacity to identify and address potential threats, ultimately strengthening network security and protecting vital information. It is imperative to recognize that the primary focus of this study was directed towards the NSL-KDD dataset. However, conducting additional research utilizing a wide range of datasets and employing advanced machine learning algorithms will provide further insights into the field of network security and intrusion detection. The results presented in this study offer a significant contribution to the ongoing endeavors in the development of reliable intrusion detection systems based on machine learning techniques. We express our aspiration that these findings serve as a catalyst for additional research and progress in network security.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eConflict of interest:\u003c/strong\u003e all authors certify that they have no affiliations with or involvement in any organization or entity with financial or non-financial interest in the subject matter or materials discussed in this manuscript\u003cstrong\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFunding\u003c/strong\u003e\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThe authors did not receive support from any organization for the submitted work.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAuthor Contributions\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIssam Trrad. Wrote the main manuscript text and prepared all figures. And reviewed the manuscript.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEthical Approval\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eWe certify that informed consent was obtained from all participants.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eData availability\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe data used in this study are available upon request from the corresponding author. The data will be made available securely and confidentially, consistent with applicable laws and regulations. Any requests for data will be reviewed on a case-by-case basis to ensure that the data are being used for legitimate research purposes.\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\u003cli\u003e\u003cspan\u003eAlrawashdeh K, Purdy C (2016) Toward an online anomaly intrusion detection system based on deep learning, in 2016 15th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 195\u0026ndash;200\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eAlter S (1996) Information Systems: A Management Perspective, 2nd edn. The Benjamin/Cummings, Menlo Park, CA\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBhattacharjee PS, Fujail AKM, Begum SA (2017) Intrusion detection system for NSL-KDD data set using vectorised fitness function in genetic algorithm, Advanced Computer Sciences and Technologies, vol. 10, no. 2, pp. 235\u0026ndash;246,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBoyce MW, Duma KM, Hettinger LJ, Malone TB, Wilson DP, Lockett-Reynolds J (2011) Human performance in cybersecurity: A research agenda, in Proceedings of the Human Factors and Ergonomics Society Annual Meeting, vol. 55, pp. 1115\u0026ndash;1119\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBrancheau JC, Wetherbe JC (1987) Key issues in information systems management MIS Quarterly, pp. 23\u0026ndash;45,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eChae H-s, Jo B-o, Choi S-H, Park T-k (2013) Feature selection for intrusion detection using NSL-KDD. Recent Adv Comput Sci 20132:184\u0026ndash;187\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eChatterjee S, Kar AK, Gupta M (2018) Alignment of IT authority and citizens of proposed smart cities in India: System security and privacy perspective. Global J Flex Syst Manage 19(1):95\u0026ndash;107\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eCheckland P, Holwell S (1998) Information, Systems, and Information Systems. John Wiley \u0026amp; Sons, Chichester\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDagar V, Prakash V, Bhatia T (2016) Analysis of pattern matching algorithms in network intrusion detection systems, in 2nd International Conference on Advances in Computing, Communication, \u0026amp; Automation (ICACCA)(Fall), 2016, pp. 1\u0026ndash;5\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDeepu T, Ravi V (2021) Supply chain digitalization: An integrated MCDM approach for inter-organizational information systems selection in an electronic supply chain. Int J Inform Manage Data Insights 1(2):100038\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDenatious DK, John A (2012) Survey on data mining techniques to enhance intrusion detection, in 2012 International Conference on Computer Communication and Informatics, pp. 1\u0026ndash;5\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDhanabal L, Shantharajah S (2015) Int J Adv Res Comput Communication Eng 4(6):446\u0026ndash;452A study on NSL-KDD dataset for intrusion detection system based on classification algorithms,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDing Y, Zhai Y (2018) Intrusion detection system for NSL-KDD dataset using convolutional neural networks, in Proceedings of the 2nd International Conference on Computer Science and Artificial Intelligence, 2018, pp. 81\u0026ndash;85\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eElmaghraby AS, Losavio MM (2014) Cyber security challenges in smart cities: Safety, security and privacy. J Adv Res 5(4):491\u0026ndash;497\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEver YK, Sekeroglu B, Dimililer K (2019) Classification analysis of intrusion detection on NSL-KDD using machine learning algorithms, in International Conference on Mobile Web and Intelligent Information Systems, pp. 111\u0026ndash;122\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eGurung S, Ghose MK, Subedi A (2019) Int J Comput Netw Inform Secur 11(3):8\u0026ndash;14Deep learning approach on network intrusion detection system using NSL-KDD dataset,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHu W, Hu W, Maybank S (2008) Adaboost-based algorithm for network intrusion detection, IEEE Transactions on Systems, Man, and Cybernetics, Part B (Cybernetics), vol. 38, no. 2, pp. 577\u0026ndash;583,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eImran HM, Abdullah AB, Hussain M, Palaniappan S, Ahmad I (2012) Intrusions detection based on optimum features subset and efficient dataset selection. Int J Eng Innovative Technol 2(6):265\u0026ndash;270\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eIngre B, Yadav A (2015) Performance analysis of NSL-KDD dataset using ANN, in 2015 International Conference on Signal Processing and Communication Engineering Systems, pp. 92\u0026ndash;96\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eIngre B, Yadav A, Soni AK (2017) Decision tree-based intrusion detection system for NSL-KDD dataset, in International Conference on Information and Communication Technology for Intelligent Systems, pp. 207\u0026ndash;218\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKar AK, Ilavarasan V, Gupta M, Janssen M, Kothari R (2019) Moving beyond smart cities: Digital nations for social innovation \u0026amp; sustainability, Information Systems Frontiers, vol. 21, no. 3, pp. 495\u0026ndash;501,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKhan M, Ibrahim, Hussain A (2021) An exploratory prioritization of factors affecting current state of information security in Pakistani university libraries. Int J Inform Manage Data Insights 1(2):100015\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKumar V, Chauhan H, Panwar D (2013) K-means clustering approach to analyze NSL-KDD intrusion detection dataset. Int J Soft Comput Eng (IJSCE), ISSN 2231\u0026ndash;2307,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKunz W, Rittel HW (1970) Issues as elements of information systems, vol. 131, Citeseer,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLakhina S, Joseph S, Verma B (2010) Feature reduction using principal component analysis for effective anomaly-based intrusion detection on NSL-KDD,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLazarevic A, Ertoz L, Kumar V, Ozgur A, Srivastava J (2003) A comparative study of anomaly detection schemes in network intrusion detection, in Proceedings of the 2003 SIAM International Conference on Data Mining, pp. 25\u0026ndash;36\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLee W, Stolfo S (1998) Data mining approaches for intrusion detection, in Proceedings of the 7th USENIX Security Symposium,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLiao Y, Vemuri VR (2002) Use of k-nearest neighbor classifier for intrusion detection. Computers \u0026amp; Security 21(5):439\u0026ndash;448\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eMeena G, Choudhary RR (2017) A review paper on IDS classification using KDD 99 and NSL KDD dataset in WEKA, in 2017 International Conference on Computer, Communications and Electronics (Comptelix), pp. 553\u0026ndash;558\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eMustafa SZ, Kar AK, Janssen M (2020) Understanding the impact of digital service failure on users: Integrating Tan\u0026rsquo;s failure and DeLone and McLean\u0026rsquo;s success model. Int J Inf Manag 53:102119\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eParsaei MR, Rostami SM, Javidan R (2016) Int J Adv Comput Sci Appl 7(6):20\u0026ndash;25A hybrid data mining approach for intrusion detection on imbalanced NSL-KDD dataset,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003ePaulauskas N, Auskalnis J (2017) Analysis of data pre-processing influence on intrusion detection using NSL-KDD dataset, in 2017 Open Conference of Electrical, Electronic and Information Sciences (eStream), pp. 1\u0026ndash;5\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eReddy GN, Reddy G (2014) A study of cyber security challenges and its emerging trends on latest technologies, arXiv preprint arXiv:1402.1842,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eReshmi T (2021) Information security breaches due to ransomware attacks-a systematic literature review. Int J Inform Manage Data Insights 1(2):100013\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eRevathi S, Malathi A (2013) Int J Eng Res Technol (IJERT) 2(12):1848\u0026ndash;1853A detailed analysis on NSL-KDD dataset using various machine learning techniques for intrusion detection,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eShahim A (2021) Security of the digital transformation, Computers \u0026amp; Security, vol. 108, 102345,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSu T, Sun H, Zhu J, Wang S, Li Y (2020) IEEE Access 8:29575\u0026ndash;29585Bat: Deep learning methods on network intrusion detection using NSL-KDD dataset,\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTavallaee M, Bagheri E, Lu W, Ghorbani AA (2009) A detailed analysis of the KDD Cup 99 data set, in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, pp. 1\u0026ndash;6\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTiwari S, Palivela H, Kumar P (2022) Classification and identification of partial outage in transmission lines using deep learning, in Recent Innovations in Computing. Springer, pp 155\u0026ndash;167\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTonge AM, Kasture SS, Chaudhari SR (2013) Cyber security: Challenges for society-literature review. IOSR J Comput Eng 2(12):67\u0026ndash;75\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eWu P-f, Shen H-j (2012) The research and amelioration of pattern-matching algorithm in intrusion detection system, in 2012 IEEE 14th International Conference on High Performance Computing and Communication \u0026amp; 2012 IEEE 9th International Conference on Embedded Software and Systems, pp. 1712\u0026ndash;1715\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eYin (2012) An improved BM pattern matching algorithm in intrusion detection system, in Applied Mechanics and Materials, vol. 148, Trans Tech Publ., pp. 1145\u0026ndash;1148\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eZhang H (2009) Design of intrusion detection system based on a new pattern matching algorithm, in 2009 International Conference on Computer Engineering and Technology, vol. 1, pp. 545\u0026ndash;548\u003c/span\u003e\u003c/li\u003e\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Network traffic, Intrusion detection system (IDS), NSL-KDD dataset, Machine learning, Network security","lastPublishedDoi":"10.21203/rs.3.rs-3869444/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-3869444/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eThe escalating intricacy and refinement of network attacks require the implementation of advanced methodologies in network security and intrusion detection. This study centers on the utilization of machine learning techniques for the categorization of network traffic, specifically employing the NSL-KDD dataset. This study investigates the efficacy of various classifiers, namely Linear Support Vector Machine (SVM), Quadratic SVM, K-Nearest Neighbor (kNN), and Long Short-Term Memory (LSTM), for the precise detection of anomalous network activity. The data is preprocessed through various techniques, including one-hot encoding and normalization, in order to enhance the performance of the model. Feature selection is utilized as a means to improve the outcomes of classification. By conducting a thorough evaluation and analysis, we present an assessment of the classifiers' performance in terms of precision, recall, and F1-score. The findings demonstrate the potential application of machine learning techniques in the field of network security, underscoring the significance of carefully choosing suitable algorithms and preprocessing approaches to achieve efficient intrusion detection. The results of our study make a significant contribution to the advancement of intrusion detection systems based on machine learning. These findings offer valuable insights for both network security practitioners and researchers in the field.\u003c/p\u003e","manuscriptTitle":"Applying Deep Learning Techniques for Network Traffic Classification: A Comparison Study on the NSL-KDD Dataset","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-01-18 07:37:48","doi":"10.21203/rs.3.rs-3869444/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"4621c7ac-e578-46f6-bed2-9f1c27b56e01","owner":[],"postedDate":"January 18th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2024-09-26T11:53:57+00:00","versionOfRecord":[],"versionCreatedAt":"2024-01-18 07:37:48","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-3869444","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-3869444","identity":"rs-3869444","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.