Sajal Saha

dblp:32/8395 · DBLP profile ↗
← Back
20ranked-venue papers
10as first author
20since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 4 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Weighted Reciprocal Rank Fusion RAG for Context-Aware DoS Attack Mitigation
abstract
Modern cybersecurity systems rely increasingly on machine learning (ML) for threat detection, yet they often fall short in delivering context-specific mitigation strategies. To bridge this gap, we propose an explanation-aware Retrieval-Augmented Generation (RAG) framework that tightly integrates supervised ML-based attack detection with Large Language Model (LLM)-driven mitigation guidance. We propose a Weighted Reciprocal Rank Fusion (WRRF)—a novel ranking method that enhances multi-query retrieval by incorporating retriever-side confidence scores. This ensures that semantically relevant and high-confidence documents from cybersecurity knowledge bases (ENISA, NIST, CISA) are prioritized during response generation. Our system begins by classifying suspicious network traffic using a Random Forest classifier trained on the UNSW-NB15 dataset. It then constructs explanation-rich prompts grounded in key anomalous features to query semantically indexed domain-specific documents. Using a multi-query strategy, the framework retrieves diverse candidate documents, which are then aggregated using WRRF to improve contextual alignment and ranking fidelity. Experimental evaluations across multiple response-generation baselines—including OpenAI, standard RAG, and RRF—demonstrate that WRRF achieves superior performance in mitigation accuracy, semantic relevance to traffic indicators, document source diversity, and response precision.
Abdullahil Kafi, Sajal Saha, Nashid Shahriar
CCNC2
2026 RAID: A Reputation-Based Aggregation for Intrusion Detection in Federated Learning
abstract
Intrusion detection in federated learning (FL) is challenged by the presence of adversarial clients who poison model updates to degrade global performance. We address this problem by proposing RAID, a reputation-based aggregation method that robustly combines client contributions in a distributed intrusion detection setting. Unlike standard Federated Averaging (FedAvg), which naively averages all updates (and can be arbitrarily manipulated by even a single malicious client), RAID assigns each client a dynamic trust weight based on the historical consistency of their updates. This approach down-weights anomalous or adversarial gradients while still preserving contributions from honest clients with diverse data. We evaluate RAID on a network intrusion detection dataset under varying poisoning attack rates (up to 40% of clients compromised), comparing against FedAvg and a Median Absolute Deviation (MAD) based robust aggregator. Key results show that RAID consistently outperforms both baselines across all attack levels, maintaining higher accuracy and F1 scores even under aggressive poisoning. For example, at 40% adversarial clients, RAID achieves an F1-0.743, significantly outperforming FedAvg and MAD (F1-0.62). These results demonstrate that RAID substantially improves robustness against poisoning attacks with minimal overhead, making it well-suited for secure federated intrusion detection in adversarial environments.
Nazanin Parvizi, Sajal Saha, Nashid Shahriar
CCNC2
2025 Deciphering Model Decisions in Android Malware Detection with Explainable AI
abstract
From fitness tracking to banking, human life is increasingly relying on mobile devices. As usage proliferates, risks associated with getting affected by malicious apps also increase. As a result, the development of mobile malware detection systems has consistently been a priority research focus over the past few decades. Traditional signature-based malware detection became obsolete with the advent of sophisticated development techniques such as polymorphism. Recent research suggests that Machine Learning (ML) based dynamic analysis is a promising approach for mobile malware detection. However, ML models often classify benign apps as malicious and viceversa. Thus, understanding the cause for identifying a particular malware kind is crucial. This study employs Random Forest ($\mathbf{R F}$) to detect Adware and Trojan malware, explaining the models and identifying the reasons for classification.
Moinul Islam Sayed, Amreen Anbar, Sajal Saha, Anwar Haque
ISNCC3
2025 Autonomous Cyber Incident Response Using Reasoning and Action
abstract
The increasing complexity and frequency of cyber threats necessitate autonomous security solutions capable of real-time detection, reasoning, and response. This paper introduces an autonomous cyber incident response framework that integrates Reasoning and Acting (ReAct) agents with Large Language Models (LLMs) to enhance cybersecurity decision-making. The proposed system features a cloud-based testbed, real-time monitoring tools (Wazuh, Suricata), and a NATS messaging system for seamless threat detection and mitigation. The ReAct agent, powered by a fine-tuned LLM, iteratively analyzes security alerts, generates context-aware mitigation strategies, and autonomously executes response actions via integrated cybersecurity tools such as firewalls. The framework demonstrates its effectiveness in real-time cyberattack mitigation, including port scanning, botnet intrusions, and SSH brute-force attacks. By leveraging LangGraph-guided decision loops and Chain-of-Thought (CoT) reasoning, the system dynamically adapts to evolving threats while reducing reliance on human intervention. Evaluations in a simulated environment highlight the scalability of the architecture and its ability to achieve low-latency, autonomous threat mitigation. The findings highlight the potential of LLM-driven security automation in modern cyber defense strategies, paving the way for future advancements in mitigating phishing, malware, and insider threats.
Sudipto Baral, Sajal Saha, Anwar Haque
IWCMC2
2025 Overcoming data limitations in internet traffic forecasting: LSTM models with transfer learning and wavelet augmentation
abstract
Accurate internet traffic prediction in smaller ISP networks is challenged by limited data availability. This paper explores this issue using transfer learning and data augmentation techniques with two LSTM-based models, LSTMSeq2Seq and LSTMSeq2SeqAtn, initially trained on a comprehensive dataset provided by Juniper Networks, Inc. and subsequently applied to smaller datasets. The datasets represent real internet traffic telemetry, offering insights into diverse traffic patterns across different network domains. Our study found that although both models performed well in single-step predictions, multi-step forecasting was more challenging, especially regarding long-term accuracy. Empirical results demonstrated that LSTMSeq2Seq outperformed LSTMSeq2SeqAtn on smaller datasets, with improvements in forecasting accuracy by up to 36.70% in MAE and 27.66% in WAPE after applying data augmentation using Discrete Wavelet Transform. The LSTMSeq2Seq model achieved an accuracy improvement from 83% to 88% for 6-step forecasts, 82% to 88% for 9-step forecasts, and 81% to 87% for 12-step forecasts, whereas LSTMSeq2SeqAtn exhibited a more stable short-term performance but higher variability in longer forecasts. Additionally, the mean absolute percentage error (MAPE) of multi-step predictions increased over longer horizons, with LSTMSeq2Seq reaching 6.74% at 12 steps and LSTMSeq2SeqAtn at 6.77%, highlighting the challenge of long-term forecasting. Variability analysis showed that while the attention mechanism in LSTMSeq2SeqAtn improved short-term prediction consistency, it also increased uncertainty in longer forecasts, as seen in the interquartile range (IQR) rising from 0.578 at 6 steps to 1.237 at 9 steps. Outlier analysis further confirmed that LSTMSeq2Seq exhibited more stable improvements, whereas LSTMSeq2SeqAtn showed increased dispersion in forecast accuracy. These findings underscore the importance of transfer learning and data augmentation in enhancing forecasting accuracy, particularly for smaller ISP networks with limited data availability. Furthermore, our analysis highlights the trade-offs between model complexity, short-term consistency, and long-term stability in internet traffic prediction.
Sajal Saha, Anwar Haque, Greg Sidebottom
Comput. Commun.1
2024 Optimizing Internet Traffic Predictions with a Novel Deep Learning EMD-KNN Framework
abstract
Internet traffic volume estimation has a significant impact on the business policies of the ISP (Internet Service Provider) industry and business successions. Forecasting the internet traffic demand helps to shed light on the future traffic trend, which is often helpful for ISPs’ decision-making in network planning activities and investments. Besides, the capability to understand future trend contributes to managing regular and long-term operations. This study aims to predict the network traffic volume demand using deep sequence methods that incorporate Empirical Mode Decomposition (EMD) based noise reduction, Empirical rule based outlier detection, and K-Nearest Neighbour (KNN) based outlier mitigation. In contrast to the former studies, the proposed model does not rely on a particular EMD decomposed component called Intrinsic Mode Function (IMF) for signal denoising. In our proposed traffic prediction model, we used an average of all IMFs components for signal denoising. Moreover, the abnormal data points are replaced by K nearest data point’s average, and the value for K has been optimized based on the KNN regressor prediction error measured in Root Mean Squared Error (RMSE). Finally, we selected the best time-lagged feature subset for our prediction model based on AutoRegressive Integrated Moving Average (ARIMA) and Akaike Information Criterion (AIC) value. Our experiments are conducted on real-world internet traffic datasets from industry, and the proposed method is compared with various statistical and traditional deep sequence baseline models. Our results show that the proposed EMD-KNN integrated prediction models outperform comparative models.
Sajal Saha, Sudipto Baral, Anwar Haque
IWCMC1
2024 Predicting and mitigating cyber threats through data mining and machine learning
abstract
With cyber threats evolving alongside technological progress, strengthening network resilience to combat security vulnerabilities is crucial. This research extends cyber-crime analysis with an innovative approach, utilizing data mining and machine learning to not only predict cyber incidents but also reinforce network robustness. We introduce a real-time data collection framework to provide up-to-date cyberattack data, addressing current research limitations. By analyzing collected attack data, we identified temporal correlations in attack volumes across consecutive time frames. Our predictive model, developed using advanced machine learning and deep learning techniques, forecasts the frequency of cyber-attacks within specific time windows, demonstrating over a 15% improvement in accuracy compared to conventional baseline models. The methodologies employed include the use of Recurrent Neural Networks (RNN) and Convolutional Neural Networks (CNN) for capturing complex patterns in time series data, and the integration of a sliding window technique to transform raw data into a format suitable for supervised learning. Our experiments evaluated the performance of various models, including ARIMA, Random Forest, Support Vector Regression, and K-Nearest Neighbors Regression, across multiple scenarios. Furthermore, we developed a Power BI platform for visualizing global cyber-attack trends, providing valuable insights for enhancing cybersecurity defences. Our research demonstrates that cyber incidents are not entirely random, and advanced AI tools can significantly enhance cybersecurity defences by analyzing patterns and trends from previous instances. This comprehensive approach not only improves prediction accuracy but also offers a robust framework for reducing the risk and impact of future cyber-crimes through enhanced detection and prediction capabilities.
Nusrat Samia, Sajal Saha, Anwar Haque
Comput. Commun.2
2024 ENIDS: A Deep Learning-Based Ensemble Framework for Network Intrusion Detection Systems
abstract
Rapid and widespread adoption of emerging Information Technology (IT) infrastructures and services in commercial and private endeavors opens new horizons for novel cyberattacks. Network Intrusion Detection Systems (NIDS) gained attention as an effective means of combating various cyber threats. Recent research demonstrates the potency of machine learning (ML) and deep learning (DL) approaches in the development of NIDS. In this paper, we propose a DL-based framework called the Ensemble Framework for Network Intrusion Detection System (ENIDS) to detect various types of cyberattacks, which includes dynamic data pre-processing, optimal feature selection, the handling of imbalanced data samples, and a DL-based ensemble model. Our DL-based ensemble model is comprised of two layers: the base learner and the meta-learner. The base learner is composed of three robust DL models: convolutional neural networks (CNN), long short-term memory (LSTM), and gated recurrent units (GRU), and the meta-learner is a deep neural network (DNN) model. The proposed framework experimented with two publicly available and popular network traffic datasets, namely UNSW-15 and CICIDS-2017. In the UNSW-15 and CICIDS-2017 datasets, our proposed framework detects cyberattacks with an accuracy of 90.6% and 99.6% and an F1-score of 90.5% and 99.6%, respectively. According to experimental findings, the proposed ensemble framework outperforms existing state-of-the-art approaches and demonstrates better performance than benchmark DL methods in terms of accuracy, F1-score, and execution time for training and testing.
Ibrahim Mohammed Sayem, Moinul Islam Sayed, Sajal Saha, Anwar Haque
IEEE Trans. Netw. Serv. Manag.3
2023 Transfer Learning Based Efficient Traffic Prediction with Limited Training Data
abstract
Efficient prediction of internet traffic is an essential part of Self Organizing Network (SON) for ensuring proactive management. There are many existing solutions for internet traffic prediction using machine and deep learning techniques. But designing individual predictive models for each service provider in the network is challenging due to data heterogeneity, scarcity, and abnormality. Moreover, the performance of the deep sequence model in network traffic prediction with limited training data has not been studied extensively in the current works. In this paper, we investigated and evaluated the performance of the deep transfer learning technique in traffic prediction with inadequate historical data leveraging the knowledge of our pre-trained model. First, we used a larger real-world traffic dataset for source domain prediction based on five different deep sequence models: Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM Encoder-Decoder (LSTM_En_De), LSTM_En_De with Attention layer (LSTM_En_De_Atn), and Gated Recurrent Unit (GRU). Then, two best-performing models, LSTM_En_De and LSTM_En_De_Atn, from the source domain with an accuracy of 96.06% and 96.05% are considered for the target domain prediction. Finally, four smaller traffic datasets, collected for four different sources and destination pairs, are used in the target domain to compare the performance of the standard learning and transfer learning in terms of accuracy and execution time. According to our experimental result, transfer learning helps to reduce the execution time for most cases, while the model's accuracy is improved in transfer learning with a larger training session.
Sajal Saha, Anwar Haque, Greg Sidebottom
CCNC1
2023 Out-of-Distribution Internet Traffic Prediction Generalization Using Deep Sequence Model
abstract
Efficient internet traffic prediction is very crucial for proactive network management. Unfortunately, it is a non-trivial task to design an effective prediction tool to capture the general pattern of complex, non-linear, and non-stationary real-world traffic. However, novel deep learning models have been developed for network traffic prediction, where they exhibit excellent performance. Most existing works assumed that training and testing data samples are independent and identically distributed (IID). But there is a high probability of having slightly or completely unknown data samples after model deployment, and the model should be able to predict them accurately. In this study, we show a comparative performance analysis among several deep sequence models using IID and out-of-distributed (OOD) samples. The prediction model average accuracy dropped significantly for OOD data samples compared to IID test data. Therefore, we proposed a hybrid architecture combining deep sequence models and discrete wavelet transformation (DWT), where models are trained using decomposed hierarchical components instead of original data. According to our experimental results, the hybrid model increases the prediction accuracy using IID samples by 2% compared to the standalone model. Also, the performance gap between IDD and OOD samples is reduced considerably by hybrid models, which indicates the outperformance of our proposed methodology to conventional deep learning models for both IDD and OOD test instances.
Sajal Saha, Anwar Haque
ICC1
2023 Examining Generative Adversarial Network for Smart Home DDoS Traffic Generation
abstract
Adversarial attacks have become a common place in network security. Neural network-based traffic classifiers have been regarded as effective tools against malicious attacks. However, their performance highly depends on the quality of the training dataset that is often hard to obtain. IoT-centric smart home network is vulnerable to adversarial attacks with a high cost to the individual. In this research, we perform a thorough study on the performance of the original GAN model towards generating flow-based IoT traffic in smart home DDoS attacks. Based on a unique IoT traffic dataset of smart home, we implemented four versions of the original GAN model by using four batch sizes per epoch during training. We captured synthetic IoT traffic at different epochs of the models, which results in a total of 200 IoT traffic datasets. Then, we evaluate the quality of the 200 synthetic datasets using an approach called train-on-synthetic, test-on-real (TSTR). Our study suggests that the original GAN can produce a quality IoT traffic of smart home DDoS attacks at most of the epochs but lacks in providing consistent performance across all the epochs of the GAN model. However, by using TSTR metrics, it is possible to identify the datasets of good quality to be used for real applications.
Md. Rashed Iqbal Nekvi, Sajal Saha, Yaser Al Mtawa, Anwar Haque
ISNCC2
2023 Wavelet-Based Hybrid Machine Learning Model for Out-of-distribution Internet Traffic Prediction
abstract
Internet traffic prediction is a crucial component for the proactive management of self-organizing networks (SON) to ensure better Quality of Service (QoS) and Quality of Experience (QoE). Modern machine learning techniques have shown outstanding performance in analyzing and predicting complex internet traffic, which has non-linear and non-stationary characteristics. But most existing works assumed that model training and testing data came from independent and identical distribution (IID), which is hardly valid in actual scenarios. Also, they considered synthetic traffic datasets, which do not have enough random properties like real-world traffic. As a result, the model’s prediction accuracy measured using IID data samples is inconsistent with the accuracy of out-of-distribution (OOD) data instances. In this study, we investigated several machine learning models’ performances using four actual traffic datasets whose distribution is different than each other. The best prediction accuracy using IID samples was 96.4% which significantly dropped when we used OOD samples to evaluate the same model. Therefore, we proposed a hybrid machine learning model combining discrete wavelet transformation to decompose original data into several hierarchical components before feeding them into a prediction model. We train our hybrid models using these detail components as features that improve our best performance using IID samples by 1%. Also, it considerably reduces the best accuracy gap of conventional machine learning models in predicting IID and OOD samples by 3.5%, 6.7%, and 2.1%, respectively, for three OOD test sets.
Sajal Saha, Anwar Haque
NOMS1
2023 L-fuzzy concept analysis using fuzzy categories
George Addison, Anahita Izadpanahi, Sajal Saha, Michael Winter 0001
Fuzzy Sets Syst.3
2023 Analyzing the Impact of Outlier Data Points on Multi-Step Internet Traffic Prediction Using Deep Sequence Models
abstract
The task of predicting Internet traffic is challenging, particularly in multi-step forecasting due to the volatile and random nature of data. In addition, real-world traffic may contain outlier data points, so developing a prediction model that integrates anomaly detection and mitigation is necessary. This paper compares several deep sequence models, such as Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM Encoder-Decoder (LSTM_En_De), LSTM Encoder-Decoder with attention layer (LSTM_En_De_Atn), and Gated Recurrent Unit (GRU), with our proposed methodology for single-step prediction. Our proposed LSTM_En_De model, integrated with outlier detection, outperforms traditional deep sequence models in single-step prediction, reducing the deviation between actual and predicted traffic by over 11%. We also apply our methodology to multi-step forecast analysis, using multiple output strategies for forecast horizons of 3, 6, 9, and 12 steps ahead. Experimental results demonstrate the effectiveness of our proposed methodology in improving the accuracy of single-step prediction and multi-step forecasting tasks, especially when dealing with outlier data points that adversely affect model accuracy. In summary, this paper investigates the challenges of real-world Internet traffic prediction, proposes a novel prediction model integrated with anomaly detection and mitigation, and compares different deep sequence models for single-step and multi-step forecasting tasks.
Sajal Saha, Anwar Haque, Greg Sidebottom
IEEE Trans. Netw. Serv. Manag.1
2022 Towards an Optimal Feature Selection Method for AI-Based DDoS Detection System
abstract
Cyber-attacks are increasing rapidly, so developing effective intrusion detection and prevention tools for a secure and safer cyberspace is crucial. DDoS (Distributed Denial of Services) is one of the most well-known digital threats, endangering any cyber-physical system. DDoS prevents the host from serving the legitimate traffic by overflowing the host node with unwanted service requests. Nowadays, machine learning-based IDS (Intrusion Detection System) uses different Feature Selection (FS) methods to extract a feature subset from a large dataset to increase the model performance and decrease the training time. In this research work, we used the UNSW-NB15 dataset [1] to conduct a comprehensive analysis for evaluating the performance of different FS techniques in DDoS attack classification using both Machine Learning (ML) and Deep Learning (DL) models. Furthermore, an Ensemble Feature Selection (EN-FS) technique called Majority Voting (MV) has been implemented to combine the individual FS method’s output to extract an optimal feature set. Our ensemble feature selection approach significantly reduces the features from 42 to 15, which is 64% less than the original features. Lastly, an extensive experiment has been performed to estimate and compare the performance of individual, ensemble, and original feature set in both ML and DL-based DDoS detection systems. According to our analysis, the ensemble feature set-based classification model exhibits higher accuracy, lower False Positive Rate (FPR), and better execution time than the other individual feature set-based models.
Sajal Saha, Annita Tahsin Priyoti, Aakriti Sharma, Anwar Haque
CCNC1
2022 Deep Sequence Modeling for Anomalous ISP Traffic Prediction
abstract
Internet traffic in the real world is susceptible to various external and internal factors which may abruptly change the normal traffic flow. Those unexpected changes are considered outliers in traffic. However, deep sequence models have been used to predict complex IP traffic, but their comparative performance for anomalous traffic has not been studied extensively. In this paper, we investigated and evaluated the performance of different deep sequence models for anomalous traffic prediction. Several deep sequences models were implemented to predict real traffic without and with outliers and show the significance of outlier detection in real-world traffic prediction. First, two different outlier detection techniques, such as the Three-Sigma rule and Isolation Forest, were applied to identify the anomaly. Second, we adjusted those abnormal data points using the Backward Filling technique before training the model. Finally, the performance of different models was compared for abnormal and adjusted traffic. LSTM_Encoder_Decoder (LSTM_En_De) is the best prediction model in our experiment, reducing the deviation between actual and predicted traffic by more than 11% after adjusting the outliers. All other models, including Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM_En_De with Attention layer (LSTM_En_De_Atn), Gated Recurrent Unit (GRU), show better prediction after replacing the outliers and decreasing prediction error by more than 29%, 24%, 19%, and 10% respectively. Our experimental results indicate that the outliers in the data can significantly impact the quality of the prediction. Thus, outlier detection and mitigation assist the deep sequence model in learning the general trend and making better predictions.
Sajal Saha, Anwar Haque, Greg Sidebottom
ICC1
2022 Towards an Ensemble Regressor Model for ISP Traffic Prediction with Anomaly Detection and Mitigation
abstract
Prediction of network traffic behavior is significant for the effective management of modern telecommunication networks. However, the intuitive approach of predicting network traffic using administrative experience and market analysis data is inadequate for an efficient forecast framework. As a result, many different mathematical models have been studied to capture the general trend of the network traffic and predict accordingly. But the comprehensive performance analysis of varying regression models and their ensemble has not been studied before for analyzing real-world anomalous traffic. In this paper, several regression models such as Extra Gradient Boost (XGBoost), Light Gradient Boosting Machine (LightGBM), Stochastic Gradient Descent (SGD), Gradient Boosting Regressor (GBR), and CatBoost Regressor were analyzed to predict real traffic without and with outliers and show the significance of outlier detection in real-world traffic prediction. Also, we showed the outperformance of the ensemble regression model over the individual prediction model. We compared the performance of different regression models based on five different feature sets of lengths 6, 9, 12, 15, and 18. Our ensemble regression model achieved the minimum average gap of 5.04% between actual and predicted traffic with nine outlier-adjusted inputs. In general, our experimental results indicate that the outliers in the data can significantly impact the quality of the prediction. Thus, outlier detection and mitigation assist the regression model in learning the general trend and making better predictions.
Sajal Saha, Anwar Haque, Greg Sidebottom
ISNCC1
2022 An Empirical Study on Internet Traffic Prediction Using Statistical Rolling Model
abstract
Real-world IP network traffic is susceptible to exter-nal and internal factors such as new internet service integration, traffic migration, internet application, etc. Due to these factors, the actual internet traffic is non-linear and challenging to analyze using a statistical model for future prediction. In this paper, we investigated and evaluated the performance of different statistical prediction models for real IP network traffic; and showed a significant improvement in prediction using the rolling prediction technique. Initially, a set of best hyper-parameters for the corresponding prediction model is identified by analyzing the traffic characteristics and implementing a grid search algorithm based on the minimum Akaike Information Criterion (AIC). Then, we performed a comparative performance analysis among AutoRegressive Integrated Moving Average (ARIMA), Seasonal ARIMA (SARIMA), SARIMA with eXogenous factors (SARIMAX), and Holt-Winter for single-step prediction. The seasonality of our traffic has been explicitly modeled using SARIMA, which reduces the rolling prediction Mean Average Percentage Error (MAPE) by more than 4% compared to ARIMA (incapable of handling the seasonality). We further improved traffic prediction using SARIMAX to learn different exogenous factors extracted from the original traffic, which yielded the best rolling prediction results with a MAPE of 6.83%. Finally, we applied the exponential smoothing technique to handle the variability in traffic following the Holt-Winter model, which exhibited a better prediction than ARIMA (around 1.5% less MAPE). The rolling prediction technique reduced prediction error using real Internet Service Provider (ISP) traffic data by more than 50% compared to the standard prediction method.
Sajal Saha, Anwar Haque, Greg Sidebottom
IWCMC1
2022 A Multi-Classifier for DDoS Attacks Using Stacking Ensemble Deep Neural Network
abstract
DDoS (Distributed Denial of Service) attacks have emerged as a serious menace to the security and integrity of data and information systems. The primary aim of this attack is to take down the targeted system and prevent legitimate users from accessing its services. Identifying a DDoS attack is a challenging task, and it must be performed before initiating any countermeasure. DDoS attack detection has been effectively applied in many studies using Machine Learning (ML) and Deep Learning (DL). However, many existing models are unable to recognize the distinct and dynamic behavior of DDoS attacks because they employ datasets that were produced a long time ago and lack up-to-date attack scenarios, do not include packet-based bi-directional traffic flow, and do not contain complete network traffic. In addition, most studies carried out binary classification, however, there are many types of DDoS attacks, each with its unique characteristics. Classifying DDoS attacks can be useful when thwarting the attack and taking preventive measures. This paper presents a multi-classifier model using stacking ensemble deep neural networks that identify several types of DDoS attacks to address the issues mentioned above. Our proposed hybrid model incorporates Convolution Neural Network (CNN), Long Short Term Memory (LSTM), and Gated Recurrent Unit (GRU), and we show that while evaluating models with large datasets such as CIC-DDoS2019, ensemble technique increases model performance. According to experimental results, our proposed model can reach an accuracy of 89.4%, which outperforms other similar methods.
Moinul Islam Sayed, Ibrahim Mohammed Sayem, Sajal Saha, Anwar Haque
IWCMC3
2022 Network Intrusion Detection and Comparative Analysis Using Ensemble Machine Learning and Feature Selection
abstract
Proper security solutions in the cyber world are crucial for enforcing network security by providing real-time network protection against network vulnerabilities and data exploitation. An effective intrusion detection strategy is capable of taking a holistic approach for protecting critical systems against unauthorized access or attack. In this paper, we describe a machine learning (ML) based comprehensive security solution for network intrusion detection using ensemble supervised ML framework and ensemble feature selection methods. In addition, we provide a comparative analysis of several ML models and feature selection methods. The goal of this research is to design a generic detection mechanism and achieve higher accuracy with minimal false positive rates (FPR). NSL-KDD, UNSW-NB15, and CICIDS2017 datasets are used in the experiment, and results show that our detection model can identify 99.3% of intrusions successfully with the lowest 0.5% of false alarms, which depicts better performance metrics compared to existing solutions.
Sajal Saha, Annita Tahsin Priyoti, Etee Kawna Roy, Frederick T. Sheldon, Anwar Haque, Sajjan G. Shiva
IEEE Trans. Netw. Serv. Manag.2