Future Internet (Mar 2023)

Resampling Imbalanced Network Intrusion Datasets to Identify Rare Attacks

  • Sikha Bagui,
  • Dustin Mink,
  • Subhash Bagui,
  • Sakthivel Subramaniam,
  • Daniel Wallace

DOI
https://doi.org/10.3390/fi15040130
Journal volume & issue
Vol. 15, no. 4
p. 130

Abstract

Read online

This study, focusing on identifying rare attacks in imbalanced network intrusion datasets, explored the effect of using different ratios of oversampled to undersampled data for binary classification. Two designs were compared: random undersampling before splitting the training and testing data and random undersampling after splitting the training and testing data. This study also examines how oversampling/undersampling ratios affect random forest classification rates in datasets with minority dataor rare attacks. The results suggest that random undersampling before splitting gives better classification rates; however, random undersampling after oversampling with BSMOTE allows for the use of lower ratios of oversampled data.

Keywords