The effect of sizes of the feature sets on intrusion detection performances

dc.contributor.authorKuy, Yoekleng
dc.contributor.authorAnantavrasilp, Isara
dc.date.accessioned2026-08-06T10:18:19Z
dc.date.available2026-08-06T10:18:19Z
dc.date.issued2017-12-28
dc.description.abstractAdaptive Intrusion Detection System (IDS) is a class of IDS that uses observed flows behaviors to detect malicious activities - usually with the aids of machine learning techniques. Most researches in this field focus on which features to be used or which classification methods to be employed. However, none have studied the impact of number of opted features on the accuracies of the anomaly detection or the smallest set of features that should be employed. This paper attempts to address these issues. We have applied feature selection algorithm, ReliefF [1] on NSL-KDD dataset [2] to select 10 most discriminative features out of 41 features. Then several machine learning algorithms are employed to classify normal and anomaly flows (both binary and multiple classes) using different set of features, each with different sizes. Experiment results show that >95% accuracies can be achieved with only 4-5 features and accuracy does not improve significantly after 6-7 features. We have also compared our results with other works and show that our work yields better results using the lower or the same number of features.
dc.identifier.citationACM International Conference Proceeding Series, 78-84, 2017
dc.identifier.doi10.1145/3178212.3178234
dc.identifier.other2-s2.0-85045882113
dc.identifier.urihttps://dspace.kmitl.ac.th/handle/123456789/8118
dc.sourceACM International Conference Proceeding Series
dc.subjectFeature selection
dc.subjectIntrusion detection system
dc.subjectMachine learning
dc.subjectNetwork traffic
dc.subjectNSL-KDD
dc.titleThe effect of sizes of the feature sets on intrusion detection performances
dc.typeConference Paper

Files

Collections