We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.NI

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Networking and Internet Architecture

Title: Performance Evaluation of Apache Spark MLlib Algorithms on an Intrusion Detection Dataset

Abstract: The increase in the use of the Internet and web services and the advent of the fifth generation of cellular network technology (5G) along with ever-growing Internet of Things (IoT) data traffic will grow global internet usage. To ensure the security of future networks, machine learning-based intrusion detection and prevention systems (IDPS) must be implemented to detect new attacks, and big data parallel processing tools can be used to handle a huge collection of training data in these systems. In this paper Apache Spark, a general-purpose and fast cluster computing platform is used for processing and training a large volume of network traffic feature data. In this work, the most important features of the CSE-CIC-IDS2018 dataset are used for constructing machine learning models and then the most popular machine learning approaches, namely Logistic Regression, Support Vector Machine (SVM), three different Decision Tree Classifiers, and Naive Bayes algorithm are used to train the model using up to eight number of worker nodes. Our Spark cluster contains seven machines acting as worker nodes and one machine is configured as both a master and a worker. We use the CSE-CIC-IDS2018 dataset to evaluate the overall performance of these algorithms on Botnet attacks and distributed hyperparameter tuning is used to find the best single decision tree parameters. We have achieved up to 100% accuracy using selected features by the learning method in our experiments
Comments: Journal of Computing and Security (Isfahan University, Iran), Vol. 9, No.1, 2022
Subjects: Networking and Internet Architecture (cs.NI)
Journal reference: Journal of Computing and Security (Isfahan University, Iran), Vol. 9, No.1, 2022
DOI: 10.22108/jcs.2022.131400.1085
Cite as: arXiv:2212.05269 [cs.NI]
  (or arXiv:2212.05269v1 [cs.NI] for this version)

Submission history

From: Mahmood Ahmadi [view email]
[v1] Sat, 10 Dec 2022 11:08:11 GMT (1368kb,D)

Link back to: arXiv, form interface, contact.