Multilevel Intrusion Detection System Based on Machine Learning Techniques.

Saved in:
Bibliographic Details
Title: Multilevel Intrusion Detection System Based on Machine Learning Techniques.
Authors: Grajales-Bustamante, J. D.1 (AUTHOR) juangrajales@itm.edu.co, Murillo-Escobar, J.2 (AUTHOR), Delgado-Trejos, Edilson3 (AUTHOR), Kendoush, Abdullah A. (AUTHOR) akendoush@augustatech.edu
Source: Journal of Engineering (2314-4912). 4/15/2026, Vol. 2026, p1-17. 17p.
Subjects: Intrusion detection systems (Computer security), Machine learning, Fuzzy clustering technique, Denial of service attacks, Support vector machines, K-nearest neighbor classification
Abstract: This paper proposes a multilevel intrusion detection system (M‐IDS) using the KDD‐Cup‐99 Dataset to detect various types of attacks on computer networks. The IDS consists of three levels and six classifiers, targeting denial of service (DoS), probing attack (PA), remote to local (R2L), and user to root (U2R) attack categories. At level 1, the first classifier identifies DoS, PA, and a class grouping R2L, U2R, and Normal. Level 2 employs three classifiers to identify attack forms corresponding to DoS, PA, R2L, U2R, and Normal. Level 3 includes two classifiers for identifying R2L and U2R attack forms. Support vector machines (SVMs), k‐nearest neighbors (k‐NNs), and semi‐supervised fuzzy c‐means (SSFCMs) classifiers were evaluated, with SVM and k‐NN performing best in levels 1 and 2, and SSFCM excelling in level 3. The proposed M‐IDS was tested using the UNSW‐NB15 Dataset, achieving errors lower than 1% in levels 1 and 2 and around 7% in level 3 for the KDD‐Cup‐99 Dataset. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Engineering (2314-4912) is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Full text is not displayed to guests.
Description
Abstract:This paper proposes a multilevel intrusion detection system (M‐IDS) using the KDD‐Cup‐99 Dataset to detect various types of attacks on computer networks. The IDS consists of three levels and six classifiers, targeting denial of service (DoS), probing attack (PA), remote to local (R2L), and user to root (U2R) attack categories. At level 1, the first classifier identifies DoS, PA, and a class grouping R2L, U2R, and Normal. Level 2 employs three classifiers to identify attack forms corresponding to DoS, PA, R2L, U2R, and Normal. Level 3 includes two classifiers for identifying R2L and U2R attack forms. Support vector machines (SVMs), k‐nearest neighbors (k‐NNs), and semi‐supervised fuzzy c‐means (SSFCMs) classifiers were evaluated, with SVM and k‐NN performing best in levels 1 and 2, and SSFCM excelling in level 3. The proposed M‐IDS was tested using the UNSW‐NB15 Dataset, achieving errors lower than 1% in levels 1 and 2 and around 7% in level 3 for the KDD‐Cup‐99 Dataset. [ABSTRACT FROM AUTHOR]
ISSN:23144904
DOI:10.1155/je/7142912