네트워크 침입탐지에서 데이터 불균형을 고려한 그래디언트 부스팅 분류기

Gradient Boosting Classifier considering Data Imbalance in Network Intrusion Detection

초록

As a way to respond to external threats due to the increase of Internet usage, researches on machine learning methods for network intrusion detection becomes more active. However the problem of data imbalance caused by minority classes is pointed out in the application of machine learning algorithms for intrusion detection. In general classification problems including network intrusion detection, the accuracy of the entire model is often the goal rather than handling the problems caused by such minority classes, so it may not be easy to deal with data imbalance. In this paper, we checked that there is a data imbalance problem in the random forest model used in network intrusion detection, and organized the composition and effect of the gradient boosting classifier for this point. The Random Forest (RF) model and the Gradient Boosting Classifier (GBC) were constructed using the KDDTrain+ data and evaluated using the KDDTest+ data. The difference in the performance of the RF model and the GBC is that the precision and recall of the GBC are higher than that of the RF model without a significant change in accuracy in low-frequency intrusion types. This effect of GBC is expected to have the effect of reducing the overall damage by detecting intrusion types that cause particularly serious damage with a higher probability.

키워드

machine learningdata imbalanceintrusion detectiongradient boosting classifierrandom forest머신러닝침입탐지데이터 불균형그래디언트부스팅 분류기랜덤포레스트
제목
네트워크 침입탐지에서 데이터 불균형을 고려한 그래디언트 부스팅 분류기
제목 (타언어)
Gradient Boosting Classifier considering Data Imbalance in Network Intrusion Detection
저자
윤한성
DOI
10.22793/indinn.2025.41.2.013
발행일
2025-06
저널명
산업혁신연구
41
2
페이지
133 ~ 140