• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Anomaly detection and attack type classification mechanism using Extra Tree and ANN


Min-Gyu Kim, Myung-Mook Han, Journal of Internet Computing and Services, Vol. 23, No. 5, pp. 79-85, Oct. 2022
10.7472/jksii.2022.23.5.79, Full Text:
Keywords: Extreme Random Forest, Artificial neural network, Anomaly Detection, Anomaly Detection and Attack type Classification, Network intrusion detection

Abstract

Anomaly detection is a method to detect and block abnormal data flows in general users' data sets. The previously known method is a method of detecting and defending an attack based on a signature using the signature of an already known attack. This has the advantage of a low false positive rate, but the problem is that it is very vulnerable to a zero-day vulnerability attack or a modified attack. However, in the case of anomaly detection, there is a disadvantage that the false positive rate is high, but it has the advantage of being able to identify, detect, and block zero-day vulnerability attacks or modified attacks, so related studies are being actively conducted. In this study, we want to deal with these anomaly detection mechanisms, and we propose a new mechanism that performs both anomaly detection and classification while supplementing the high false positive rate mentioned above. In this study, the experiment was conducted with five configurations considering the characteristics of various algorithms. As a result, the model showing the best accuracy was proposed as the result of this study. After detecting an attack by applying the Extra Tree and Three-layer ANN at the same time, the attack type is classified using the Extra Tree for the classified attack data. In this study, verification was performed on the NSL-KDD data set, and the accuracy was 99.8%, 99.1%, 98.9%, 98.7%, and 97.9% for Normal, Dos, Probe, U2R, and R2L, respectively. This configuration showed superior performance compared to other models.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Kim, M. & Han, M. (2022). Anomaly detection and attack type classification mechanism using Extra Tree and ANN. Journal of Internet Computing and Services, 23(5), 79-85. DOI: 10.7472/jksii.2022.23.5.79.

[IEEE Style]
M. Kim and M. Han, "Anomaly detection and attack type classification mechanism using Extra Tree and ANN," Journal of Internet Computing and Services, vol. 23, no. 5, pp. 79-85, 2022. DOI: 10.7472/jksii.2022.23.5.79.

[ACM Style]
Min-Gyu Kim and Myung-Mook Han. 2022. Anomaly detection and attack type classification mechanism using Extra Tree and ANN. Journal of Internet Computing and Services, 23, 5, (2022), 79-85. DOI: 10.7472/jksii.2022.23.5.79.