TalMaIka/Modern-NIDS

Modern type Network intrusion detection system.

★ 0Forks 1PythonGitHub ↗Compare

README

Modern Network Intrusion Detection System (NIDS)

Authors

  • Tal Malka
  • Yann Chicheportiche

Project Overview

This project aims to develop a Network Intrusion Detection System (NIDS) leveraging machine learning techniques to detect and classify diverse network intrusions in real-time.

Research Question

Which machine learning algorithm provides the best performance for real-time intrusion detection and classification on modern datasets (CIC-IDS2017), considering accuracy, detection speed, robustness, and false positive management?

Problem Statement

Cybersecurity Threats

  • Global cyberattack losses exceed $6 trillion annually.
  • Increasing sophistication of attacks (zero-day vulnerabilities, DDoS, infiltration attempts).

Limitations of Traditional IDS

  • Signature-based/rule-based systems struggle to detect novel (zero-day) attacks.
  • Polymorphic malware and evolving threats evade static detection methods.

Need for Adaptive Approaches

  • Real-time analysis of complex network traffic is crucial.
  • Machine learning techniques offer adaptability to emerging threats.

Project Goals

  • Develop a machine learning-based NIDS that accurately detects and classifies cyber threats.
  • Evaluate multiple ML algorithms (Random Forest, KNN, Logistic Regression, Voting Classifier) on modern datasets (CIC-IDS2017).

Related Work

Extensive research has been conducted on ML techniques for intrusion detection. Some key findings:

  • Random Forest & Decision Trees: Strong performance but limited scalability.
  • Hybrid/Ensemble Methods: Improved accuracy but lacked real-time adaptability.
  • Advanced Techniques (SVM, Neural Networks): High accuracy but require extensive preprocessing.

Dataset Used: CIC-IDS2017

The CIC-IDS2017 dataset is utilized for training and testing, containing realistic cyberattack scenarios, including:

  • Portscan - Identifying open or vulnerable ports.
  • DoS/DDoS Attacks - Flooding services with excessive requests.
  • Infiltration - Exploiting open ports for unauthorized access.
  • Botnet & Brute Force Attacks - Compromising machines and guessing login credentials.
  • Web Attacks (SQL Injection, XSS) - Exploiting web applications.

Feature Selection and Data Processing

  • Checked for missing data and removed irrelevant variables.
  • Exploratory data analysis performed to understand network traffic behavior.

Machine Learning Models Evaluated

  1. Random Forest (RF)
  2. K-Nearest Neighbors (KNN)
  3. Logistic Regression (LR)
  4. Voting Classifier (Ensemble Approach)

Key Findings and Innovations

Performance Metrics (False Positives)

Algorithm False Positives False Positive Rate
Random Forest 61 0.013%
KNN 699 0.14%
Logistic Regression 68,522 10.876%
Voting Classifier 699 0.036%

Innovations

  • Use of Modern Datasets - CIC-IDS2017 captures contemporary attack patterns.
  • Algorithmic Comparison - Evaluated multiple models beyond traditional methods.
  • False Positive Reduction - Focused on reducing false alarms for practical deployment.
  • Real-Time Adaptability - Ensured models could scale to handle large network traffic volumes.

Conclusion

This study highlights the importance of machine learning in modern NIDS solutions. Unlike legacy IDS approaches, our ML-powered NIDS leverages modern datasets to enhance detection accuracy while minimizing false positives. The Voting Classifier and Random Forest models demonstrated strong performance, making them suitable for real-world cybersecurity applications.

Future Work

  • Implement deep learning techniques for further improvement.
  • Optimize real-time processing for large-scale network environments.
  • Integrate adaptive learning models to keep up with evolving threats.

Project Cloud Link

Access Project Files

How to Use the Code

  1. Install Dependencies:
    pip3 install -r requirements.txt
  2. Run the Model Training:
    python3 <Model>.py

Contributors

TalMaIka

Issues