We found a match
Your institution may have access to this item. Find your institution then sign in to continue.
- Title
Benchmarking full version of GureKDDCup, UNSW-NB15, and CIDDS-001 NIDS datasets using rolling-origin resampling.
- Authors
Chew, Yee Jian; Lee, Nicholas; Ooi, Shih Yin; Wong, Kok-Seng; Pang, Ying Han
- Abstract
Network intrusion detection system (NIDS) is a system that analyses network traffic to flag malicious traffic or suspicious activities. Several recent NIDS datasets have been published, however, the lack of baseline experimental results on the full version of datasets had made it difficult for researchers to perform benchmarking. As the train-test distribution of the datasets has yet to be pre-defined by the creators, this further obstruct the researchers to compare the performance unbiasedly across each of the machine classifiers. Moreover, cross-validation resampling scheme have also been addressed in the literatures to be inappropriate in the domain of NIDS. Thus, rolling-origin – a standard resampling technique which is also known as a common cross-validation scheme in the forecasting domain is employed to allocate the training and testing distributions. In this paper, rigorous experiments are conducted on the full version of the three recent NIDS datasets: GureKDDCup, UNSW-NB15, and CIDDS-001. While the datasets chosen might not be the latest available datasets, we have selected them as they include the essential IP address fields which are usually missing or removed due to some sort of privacy concerns. To deliver the baseline empirical results, 10 well-known classifiers from Weka are utilized.
- Subjects
INTERNET protocol address
- Publication
Information Security Journal: A Global Perspective, 2022, Vol 31, Issue 5, p544
- ISSN
1939-3555
- Publication type
Academic Journal
- DOI
10.1080/19393555.2021.1985191