Home > Published Issues > 2024 > Volume 15, No. 1, 2024 >
JAIT 2024 Vol.15(1): 87-103
doi: 10.12720/jait.15.1.87-103

B-DT Model: A Derivative Ensemble Method to Improve Performance of Intrusion Detection System

Amarudin 1,2, Ridi Ferdiana 1,*, and Widyawan 1
1. Department of Electrical Engineering and Information Technology, Universitas Gadjah Mada, Yogyakarta, Indonesia
2. Faculty of Engineering and Computer Science, Universitas Teknokrat Indonesia, Lampung, Indonesia
Email: amarudin@mail.ugm.ac.id, amarudin@teknokrat.ac.id (A.); ridi@ugm.ac.id (R.F.); widyawan@ugm.ac.id (W.)
*Corresponding author

Manuscript received June 25, 2023; revised July 20, 2023; accepted September 4, 2023; published January 18, 2024.

Abstract—In cyber security, system security must be prioritized. Therefore, to improve system security, a system device called an Intrusion Detection System (IDS) is needed. IDS is a system that can detect suspicious activity on a system or network. The constraint of IDS is many types of attacks appear now, making it difficult to detect them. Therefore, many IDS based on machine learning have been applied to overcome this constraint. And machine learning has been widely adopted to improve IDS performance. However, false detection occurs frequently. The problem raised in this study is the large number of false detections that still occur. The main objective of this study is to reduce the occurrence of false detection in IDS. Then, to achieve this objective, this paper proposes a model called the B-DT model. The Bagging-DT (B-DT) model combines the Bagging technique ensemble-base and Decision Tree (DT) classifier. The B-DT model was trained and evaluated on NSL-KDD and UNSW-NB15 datasets. The results showed that it can reduce false detection from 11,305 data to 243 data in the NSL-KDD dataset. Besides that, the B-DT model can reduce false detection from 2,504 data to 871 in the UNSW-NB15 dataset. In addition, model performance has increased in accuracy, precision, recall, f1-score, and kappa-score. Based on the results, the B-DT model’s performance can achieve an accuracy of 99.45% on the NSL-KDD dataset and 79.67% on the UNSW-NB15 dataset. This model can work well not only on binary-class data but also on multi-class labeled data. The statistical evaluation shows this model has increased significantly compared to other models. These results suggest that the proposed B-DT model can effectively enhance the performance of IDS and be a promising solution for practical applications.
 
Keywords—cyber security, network security, intrusion detection system, ensemble learning, bagging, machine learning, decision tree

Cite: Amarudin, Ridi Ferdiana, and Widyawan, "B-DT Model: A Derivative Ensemble Method to Improve Performance of Intrusion Detection System," Journal of Advances in Information Technology, Vol. 15, No. 1, pp. 87-103, 2024.

Copyright © 2024 by the authors. This is an open access article distributed under the Creative Commons Attribution License (CC BY-NC-ND 4.0), which permits use, distribution and reproduction in any medium, provided that the article is properly cited, the use is non-commercial and no modifications or adaptations are made.