Published October 30, 2020 | Version v1

A Machine Learning Model for Network Intrusion Detection System Using Hidden Markov Model

  • 1. MSc. Computer Science, Kwame Nkrumah University of Science and Technology(KNUST), Kumasi, Ghana
  • 2. Senior Lecturer, Department of Computer Science, KNUST, Kumasi, Ghana
  • 3. Ghana Technology University College, Ghana
  • 4. Professor, Department of Computer Science, KNUST, Kumasi, Ghana

Description

Cyberattacks are becoming more sophisticated as
attackers continuously use diverse strategies and
tactics to attack target systems. To avert this
impending threat, various possible solutions have
been implemented and a variety of security systems
keeps emerging. One of these solutions is intrusion
detection systems (IDS). The challenge in developing
a model that is efficient to detect intrusion is directly
dependent on the features selected during the training
process and also to detect known and unknown
attacks. In this thesis a machine learning model is
proposed based on a Hidden Markov Model. The
model was trained and tested with data from the NSL
KDD dataset, which was selected based on four
categories of attacks. The relevant features for
training were selected from the dataset based on the
scores evaluated from a Laplacian model. New
features were extracted from the selected features
based on variance from a Principal Component
Analysis to decrease the dimensionality of the
dataset. K-Means Algorithm was utilized in mapping
the extracted data into a new feature space for
training. The proposed model produced an accuracy
of 83.85% which outperformed the accuracies of the
existing models built with the Support Vector
Machine (SVM), Random Forest (RF), Deep Belief
Network (DBN), and the Convolutional Neural
Networks (CNN) which had 71.30%, 74.18%,
71.91% and 80.13% respectively.
Keywords: Cyberattacks, intrusion, security,
detection, Hidden Markov Model

Files

11 Paper 01092030 IJCSIS Camera Ready pp103-112.pdf

Files (878.9 kB)