Tomek Links and Random Undersampling for Infiltration Attack Detection in Imbalanced CSE-CIC-IDS2018 Dataset
Abstract
Several previous studies have used the CSE-CIC-IDS2018 dataset to develop intrusion detection systems (IDSs) with advanced models, such as long short-term memory (LSTM). However, these studies underscore the imbalance in the dataset, where the 'Benign' label is much more common than some attack labels, such as 'Infiltration'. This study aims to build and improve a model for detecting infiltration attacks using the CSE-CIC-IDS2018 dataset. The first step after obtaining the dataset is preprocessing, which involves applying a label encoder, performing principal component analysis (PCA) for dimension reduction, and normalizing the features. The next step is to apply undersampling and use the LSTM as a prediction model. We mitigate imbalance in the dataset by combining several undersampling methods, including Tomek links and random undersampling (RUS). Finally, receiver operating characteristic (ROC), area under the curve (AUC), and g-mean methods optimize the threshold for each prediction method. The test results show that PCA can improve the efficiency of the LSTM model, with the LSTM + PCA model being 1.7× smaller and 1.1x faster. Then Tomek links + RUS is proven to provide the best sensitivity and G-mean compared to the base model, namely 0.73 and 0.80, respectively. Finally, threshold optimization using the ROC curve further enhances the model's predictive performance, increasing its sensitivity to 0.82.
References
L. Hou, J. Han, B. Yang. Y. Guo, X. Wang, and G. Yang. "Research on attack trapping methods for multi-stage infiltration attacks," in 2023 International Conference on Computer Simulation and Modeling. Information Security (CSMIS). IEEE, 2023, pp. 556-560.
F. Laghrissi, S. Douzi, K. Douzi, and B. Hssina, "Intrusion detection systems using long short-term memory (LSTM)," Journal of Big Data, vol. 8, no. 1. p. 65, dec 2021. [Online]. Available: https://doi.org/10.1186/s40537-021-00448-4
A. Z. Yonis, "Network communication intrusion detection and classifi-cation security techniques," in 2022 IEEE Integrated STEM Education Conference (ISEC), 2022, pp. 455-459.
L. Göcs and Z. C. Johanyák, "Identifying relevant features of cse-cic-ids2018 dataset for the development of an intrusion detection system." Intelligent Data Analysis, vol. 28, по. 6, pp. 1527-1553, 2024,
V. Bulavas. "Improving machine learning model performance on de-tection of network infiltration," in 2021 14th International Conference on Human System Interaction (HSI). IEEE, 2021, pp. 1-6.
A. Thumpati and Y. Zhang, "Towards optimizing performance of machine learning algorithms on unbalanced dataset," in CS & IT Conference Proceedings, vol. 13, no. 19. CS & IT Conference Proceedings, 2023.
T. Elhassan, M. Aljurf et al., "Classification of imbalance data using tomek link (t-link) combined with random under-sampling (rus) as a data reduction method," Global J Technol Optim S. vol. 1, no. $1, 2016.
M. Andrecut, "Attack vs benign network intrusion traffic classifica-tion." arXiv preprint arXiv:2205.07323, 2022.
M. Antunes, L. Oliveira, A. Seguro, J. Veríssimo, R. Salgado, and T. Murteira, "Benchmarking deep learning methods for behaviour-based network intrusion detection, in Informatics, vol. 9, no. 1. MDPI, 2022, p. 29.
L Ruisen, D. Songyi, W. Chen, C. Peng, T. Zuodong, Y. YanMei, and W. Shixiong. "Bagging of xgboost classifiers with random under-sampling and tomek link for noisy label-imbalanced data," in IOP Conference series: Materials science and engineering, vol. 428, по. 1. IOP Publishing, 2018, p. 012004.
M. Bach and A. Werner, "Improvement of random undersampling to avoid excessive removal of points from a given area of the ma-jority class," in International Conference on Computational Science. Springer, 2021, pp. 172-186.
J. Hancock, J. M. Johnson, and T. M. Khoshgoftaar, "A comparative approach to threshold optimization for classifying imbalanced data," in 2022 IEEE 8th International Conference on Collaboration and Internet Computing (CIC). IEEE, 2022, pp. 135-142.
(13) J. M. Johnson and T. M. Khoshgoftaat, "Robust thresholding strategies for highly imbalanced and noisy data in 2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA) IEEE 2021, pp. 1182-1188.
M. Ghurab, G. Gaphari, F. Alshami, R. Alshamy, and S. Othman, "А detailed analysis of benchmark datasets for network intrusion detection system," Asian Journal of Research in Computer Science, vol, 7, no. 4. pp. 14-33, 2021.
D. Stiawan. D. Wahyudi, T. W. Septian, M. Y. Idris, and R. Budiano, "The development of an internet of things Got) network traffic dataset with simulated attack dana." Journal of Internet Technology, vol. 24 по. 2, pp. 345-356, 2023,
L. Yung. Z. Chen, C. Wang 7. Zhang. S. Bosoma, P. Cao, C. Adam, A. Withers, Z. Kalharczyk, R. K. Iyer, and G. Wang. "True attacks, attack attempts, or benigs triggers as empirical measurement of network alerts in a security operations center. in 33nd USENIX Security Sump USENIX Security 241 Philadelphia, PA USENIX Association, Aug 2024, pp. 1525-1542 [Online]. Available: https://www.usenix.org/conference/usenixsecurity 24/presentation/yang-lamin
A. L. Krall. M. E. Kuhl. S. F. Moskal, and 5. 1. Yang, "Assessing the likelihood of cyber network infiltration using rase-event simulation, in 2016 IEEE Symposium Series on Computational Intelligence (SSCI) IEEE 2016, pp. 1-7.
V. Malik, A. Khanna, N. Sharma, and S. Nalluri. "Advanced persistent thenats (apts): Detection techniques and mitigation strategies, Inter national Journal of Global tusovations and Solutions (GIS), August 2024
S. Xie, H. Lin, T. Ma, K. Peng, and 7. Sun, "Prediction of joust roughness coefficiem via hybrid machine learning model combined with principal components analysis," Journal of Rock Mechanics and Geotechnical Engineering, vol. 17, по. 4, pp. 2291-2306, 2005.
A. G. Putrada, N. Alamsyah, L. D. Oktaviani, and M. N. Fauzan, "Lam for web visit forecasting with genetic algorithm and predictive band width allocation," in 2024 International Conference on Information Technology Research and Innovation (ICITRI) IEEE, 2004, pp. 53-58.
A. G. Putrada, N. Alamsyah. M. N. Fauzan, and S. F. Pane, "Ns-sv Bolstering chicken egg harvesting prediction with normalization and standardization," JUITA: Jurnal Informatika, pp. 11-18, 2023
A. G. Putrada. I. D. Oktaviani, M. N. Fauzan, and N. Alamsyah, "Con-bam for mfec-based speech recognition on smart mitrors for edge computing command, Journal of Dinda Data Science, Information Technology, and Data Analstics, vol. 4, no. 2. pp. 63-74, 2024.
J. L. Leevy and T. M. Khoshgoftaar. "A survey and analysis of intrusion detection models based on cso-cio-ids2018 big data," Journal of Rig Data, vol. 7, no. 1, p. 104, 2020
S. Munawar, N. Javuid, Z. A. Khan, N. L Chaudhary, M. A. Z. Raja. A. H. Milyani, and A. Ahmed Azhari, "Electricity theft detec tion in snart grids using a hybrid bigru-bilium model with feature engineering-based preprocessing" Sensura, vol. 22, no. 20. p. 7818. 2002.
(25) R. Zoech, J. Hancock, and T. M. Khoshgoftaar, "Detecting web attacks using random undersampling and ensemble learners, Journal of Mix Dutt, vol. 8, no. 1, p. 75, 2021.
T. Wongvorachan, P. Meesad, and K. Kendprasop, "A comparison of undersampling, oversampling, and hybrid resampling for imbalanced chssification," bformation, vol. 14. om. 1. p. 54, 2023. [Online]. Available: btps://www.mdpi.com/2078-2489/14/1/54
A. G. Putrada, 1. D. Oktaviani, M. N. Fauzan, and N. Alamsyalı. "Quantifying student model accuracy via sample size and soft label mse: Insights into label quality," in 2024 Ninth International Confer ence on Informatics and Computing (1010) IEEE 2004, pp. 1-6.
A. G. Putrada, N. Alamsyah, S. F. Pane, M. N. Fmazan, and D. Perdana. "Auc matimization for flood attack detection on sogtt with imbalanced dataset, in 2023 International Conference on Information Technology Research and Junovation (ICITRI) IEEE, 2023, pp. 133-138.
J. Archana and A. Anertha. "Latmeni: Revolutionizing intrusion detection through adaptive leaming and mutual information analysis," in 2024 Thind International Conference on Distributed Computing and Electrical Circuity and Electronics ICDCECE IEEE, 2024. pp. 1-7.
C. N. Obiora, A. Ali, and A. N. Hasan, "Finding the optimum horizon for short-term solar irradiance forecasting using long short-term memory (sam) network." in 2022 11th buernational Conference on Power Science and Engineering (ICPSEL IEEE, 2022. pp. 148-152



