University of Tennessee at Chattanooga
A comparative study of the performance of machine learning methods and deep neural networks in intrusion detection
Abstract
dc:description.abstractIntrusion detection systems (IDS) can be improved by using machine learning to teach the IDS what traffic is normal and therefore should be allowed into a network, or what traffic is abnormal and should be denied access to a network. The performance of intrusion detection systems can be improved through the use of machine learning methods that can accurately identify and classify normal attack versus attack traffic. There are numerous machine learning methods that can be employed for the purpose of improving intrusion detection. We use the NSL-KDD dataset to evaluate various machine learning models in order to determine the most relevant features for differentiating between normal and attack traffic. Then, we perform SHAP analysis to determine which features have greater effect on the models.
Degree
thesis:*- Grantor dc:publisher
- University of Tennessee at Chattanooga
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Artis, Milan
- Contributors dc:contributor
-
- Sakib, Shahnewaz Karim
- Kizza, Joseph; Qin, Hong
- College of Engineering and Computer Science
Subjects
dc:subject × 3Rights
dc:rights- Language dc:language
- English, eng
Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholar.utc.edu/theses/966
- OAI identifier oai:identifier
- oai:scholar.utc.edu:theses-2142