A QUANTITATIVE CORRELATIONAL STUDY OF ASSESSING THE EFFECTIVENESS OF RANDOM FOREST IN REDUCING FALSE POSITIVES IN INTRUSION DETECTION SYSTEMS FOR ENTERPRISE NETWORKS
Authors/Creators
- 1. TUPT-NS-T-4A-T, Group 1, Technological University of the Philippines, Taguig, Km 14 East Service Road, Western Bicutan, Taguig City, Philippines
Description
The Intrusion Detection Systems (IDS) have been vital in ensuring that enterprise networks are not affected by cyber threats by checking traffic and detecting abnormal activities. Although important, IDS is likely to have high false positive rates that may bombard security staff and decrease efficiency. Machine learning has come up as a promising solution to this problem, where the Random Forest (RF) has been identified as an ensemble-based technique where the detection is enhanced and the number of false alarms reduced. This paper analyses how TUP-T students perceive the effectiveness of the Random Forest in reducing false positive in IDS in enterprise networks. The qualitative research design was employed under descriptive research design in which a survey questionnaire was viewed as the prime data collection tool. The survey was also distributed to 100 participants through the Google Forms over the 2 weeks and contained both demographics and the knowledge of the application of the IDS and the Random Forest, attitudes towards the usefulness of the RF and the perceived benefits and problems of its utilization as well. The quantification of respondent measures was performed on Likert scale and quantification of data was done using the assistance of descriptive statistics via frequencies, percentages/ mean scores. These types of ethical concerns such as voluntary participation, anonymity and confidentiality were thoroughly observed. The results revealed a positive mark on the level of awareness of the interviewees since most of them expressed a high level of agreement of the claims that random forest improves precision of IDS, reduces false positives, and even has the ability to perform superiorly as compared to traditional instruments of detection. Other benefits that were identified by the participants included improved efficiency, less workload, and greater confidence in the safety of enterprise security mechanisms, as well as the resource needs and the complexity of the implementation process. The research adds a human aspect to the current literature on the technical research with respect to showing that user perceptions are corroborated with empirical research on the effectiveness of Random Forest. In general, the results indicate that Random Forest has a great potential to be applied to enterprise IDS, which enhances the trust and credibility of cybersecurity.
Files
V5I1048.pdf
Files
(219.5 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:0b94123854e7bb4283e97bc104ef6092
|
219.5 kB | Preview Download |