Multiclass Intrusion Detection in Computer Networks: Comparative Study of Architectures, Balancing and Attribute Selection on the CSE-CIC-IDS2018

Vol 57, 2025 - 340895
Extended Abstracts (EA)
Favorite this paper
How to cite this paper?
Abstract

This extended abstract reports a comparative experimental study of multi-class detection of network intrusions, performed without a GPU on the CSE-CIC-IDS2018, consisting of 15 classes. The protocol was organized in four chained stages. At each stage, the choice is made by an explicit hierarchical criterion and recorded in a persistent state, allowing auditing and re-execution of the chain. The procedure selects CatBoost, SMOTE-ENN and mRMR with 15
attributes. In the test reserved and kept isolated during tuning, the final configuration gets macro recall of 0.8803, MCC of 0.8382, and macro FPR of 0.0086. Attribute selection reduces representation to 19.5% of the original dimensionality and preserves 99.8% of macro recall. Relative to baseline, the final model reduces the projected rate of alarms by approximately half.

Share your ideas or questions with the authors!

Did you know that the greatest stimulus in scientific and cultural development is curiosity? Leave your questions or suggestions to the author!

Sign in to interact

Have a question or suggestion? Share your feedback with the authors!

Institutions
  • 1 Universidade Federal de Alagoas | (Universidade Federal de Alagoas)
  • 2 Universidade Federal de Alagoas
Track
  • OA – Other Applications in OR
Keywords
Intrusion Detection
Machine Learning
Class Unbalance
CIC-IDS-2018
IDS