Error-correcting Ability Based Collaborative Multi-Layer Selective Classifier Ensemble Model for Intrusion Detection

Limin Lu,Shaohua Teng,Wei Zhang,Zhenhua Zhang,Dongning Liu,Xiaozhao Fang
DOI: https://doi.org/10.1109/cscwd.2019.8791854
2019-01-01
Abstract:Ensemble classifier, by combining multiple classifiers, can often achieve better performance than single classifiers in intrusion detection. Although some ensemble methods have been used for intrusion detection, most of them directly fuse detection outputs after multiple classifiers a re generated. It potentially reduce the overall performance and flexibility. Aiming at achieving a high-precision intrusion detection model with good generalization performance and robustness, an error-correcting ability based collaborative multi-layer selective classifier ensemble model is proposed in this paper, named ML-SCEM. In the ML-SCEM, a novel multi-layer structure consisting of 5 continuous layers is designed, each layer of which is equivalent to a binary classification. In each layer, an error-correcting based selective classifier ensemble method(SCEM) is used to select the main classifier and error-correcting components from M pre-selected base classifiers to generate an ensemble classifier suitable for this layer classification category. Furthermore to improve time efficiency and detection performance, the original dataset is divided into 3 parts of TCP, UDP and ICMP according to the network protocol, so that the three parts are collaboratively detected. The performance of the proposed ML-SCEM is evaluated and compared on the NSL-KDD dataset. It achieves accuracy of 97.07%, false positive rate of 1.58% and efficiently detects various types of attacks.
What problem does this paper attempt to address?