{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T00:22:23Z","timestamp":1762042943815,"version":"build-2065373602"},"reference-count":22,"publisher":"Engineering and Technology Publishing","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["jcm"],"published-print":{"date-parts":[[2021]]},"abstract":"<jats:p>Non-parametric Nearest Neighbor is an algorithm seeking for the closest data points based on the Euclidean Norm (the standard distance between two data points in a multidimensional space). The classical K-nearest Neighbor (KNN) algorithm applies this theory to find K data points in a vicinity of the considering data, then uses majority voting to label its category. This paper proposes a modification to the original KNN to improve its accuracy by changing that Euclidean Norm based on Shannon-Entropy theory in the context of Network Intrusion Detecton System. Shannon-Entropy calculates the importance of features based on the labels of those data points, then the distance between data points would be re-calculated through the new weights found for these features. Therefore, it is possible to find the more suitable K data points nearby. NSL - KDD dataset is used in this paper to evaluate the performance of the proposed model. A comparison is drawn between the results of the classic KNN, related work on its improvement and the proposed algorithm as well as novel deep learning approaches to evaluate its effectivenes in different scenarios. Results reveal that the proposed algorithm shows good performance on NSL - KDD data set. Specifically, an accuracy up to 99.73% detecting DoS attacks is obtained, 5.46% higher than the original KNN, and 1.15% higher than the related work of M-KNN. Recalculating the Euclidean-Norm distance retains the contribution of the features with low importance to the data classification, while assuring that features with higher importance will have a higher impact. Thus, the proposal does not raise any concern for losing information, and even achieves high efficiency in the classification of features and data classification.<\/jats:p>","DOI":"10.12720\/jcm.16.8.347-354","type":"journal-article","created":{"date-parts":[[2021,10,20]],"date-time":"2021-10-20T07:51:00Z","timestamp":1634716260000},"page":"347-354","source":"Crossref","is-referenced-by-count":5,"title":["Improvement of K-nearest Neighbors (KNN) Algorithm for Network Intrusion Detection Using Shannon-Entropy"],"prefix":"10.12720","author":[{"name":"School of Information and Communication Technology, Hanoi University of Science and Technology, Hanoi, Vietnam","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nguyen Gia","family":"Bach","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Le Huy","family":"Hoang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tran Hoang","family":"Hai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"4977","published-online":{"date-parts":[[2021]]},"reference":[{"key":"ref0","doi-asserted-by":"publisher","unstructured":"[1] A. B. Mohamed, N. B. Idris, and B. Shanmugam, \"A brief introduction to intrusion detection system,\" Trends in Intelligent Robotics, Automation, and Manufacturing - Kuala Lumpur, vol. 330, pp. 263-271, Nov. 28, 2012.","DOI":"10.1007\/978-3-642-35197-6_29"},{"key":"ref1","doi-asserted-by":"publisher","unstructured":"[2] L. Mehrotra and P. S. Saxena, \"An assessment report on: statistics-based and signature-based intrusion detection techniques,\" Information and Communication Technology, vol. 625, pp. 321-327, October 2017.","DOI":"10.1007\/978-981-10-5508-9_31"},{"key":"ref2","unstructured":"[3] J. Veeramreddy and K. M. Prasad, \"Anomaly-Based intrusion detection system,\" Computer and Network Security, June 2019."},{"key":"ref3","unstructured":"[4] V. D. Kunwar, \"Analyzing of zero day attack and its identification techniques,\" in Proc. First International Conference on Advances in Computing & Communication Engineering, 2014, pp. 11-13."},{"key":"ref4","doi-asserted-by":"publisher","unstructured":"[5] Z. Zhang, \"Introduction to machine learning: K-nearest neighbors\" Ann Transl Med., vol. 4, no. 11, p. 218, Jun. 2016,","DOI":"10.21037\/atm.2016.03.37"},{"key":"ref5","unstructured":"[6] G. Jianping, D. Lan, Z. Yuhong, and X.Taisong, \"A new distance-weighted k -nearest neighbor classifier,\" J. Inf. Comput. Sci., 2011."},{"key":"ref6","doi-asserted-by":"publisher","unstructured":"[7] B.Bobba and S. Kailasam, \"Fast kNN classifiers for network intrusion detection system,\" Indian Journal of Science and Technology, vol. 10, no. 14, April 2017.","DOI":"10.17485\/ijst\/2017\/v10i14\/93690"},{"key":"ref7","doi-asserted-by":"publisher","unstructured":"[8] H. Benaddi, K. Ibrahimi, and A. Benslimane, \"Improving the intrusion detection system for NSL-KDD dataset based on PCA-Fuzzy Clustering-KNN,\" in Proc. 6th International Conference on Wireless Networks and Mobile Communications (WINCOM), Marrakesh, Morocco, 2018, pp. 1-6.","DOI":"10.1109\/WINCOM.2018.8629718"},{"key":"ref8","unstructured":"[9] NSL-KDD data set for network-based intrusion detection systems. [Online]. Available: http:\/\/nsl.cs.unb.ca\/KDD\/NSLKDD.html, March 2009."},{"key":"ref9","unstructured":"[10] B. Senthilnayaki, K. Venkatalakshmi, and A. Kannan, \"Intrusion detection system using fuzzy rough set feature selection and modified KNN classifier,\" Int. Arab J. Inf. Technol., 16, 746-753, 2019."},{"key":"ref10","unstructured":"[11] S. Alaa and A. Amneh, \"A professional comparison of C4.5, MLP, SVM for network intrusion detection based feature analysis,\" ICGST Journal of Computer Networks and Internet Research, 2015."},{"key":"ref11","unstructured":"[12] X. Lei, Y. Pingfan, and C. Tong, \"Best first strategy for feature selection,\" in Proc. International Conference on Pattern Recognition, 1988, pp. 706-708."},{"key":"ref12","unstructured":"[13] M. H\u00e9ctor and Y. Georgios, \"Genetic search feature selection for affective modeling: A case study on reported preferences,\" in Proc. 3rd International Workshop on Affective Interaction in Natural Environments, 2010."},{"key":"ref13","unstructured":"[14] D. Yalei and Z. Yuqing, \"Intrusion detection system for NSL-KDD dataset using convolutional neural networks,\" in Proc. 2nd International Conference on Computer Science and Artificial Intelligence, 2018, pp. 81-85."},{"key":"ref14","unstructured":"[15] T. Ciz, S. Vishwas, and B. Narayanaswamy, \"Usefulness of DARPA dataset for intrusion detection system evaluation,\" in Proc. SPIE 6973, Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security, 2008."},{"key":"ref15","doi-asserted-by":"publisher","unstructured":"[16] D. D. Proti\u0107, \"Review of KDD Cup '99, NSL-KDD and Kyoto 2006+ datasets,\" Vojnotehnicki Glasnik\/Military Technical Courier, vol. 66, no. 3, pp. 580-596, 2018.","DOI":"10.5937\/vojtehg66-16670"},{"key":"ref16","doi-asserted-by":"publisher","unstructured":"[17] A. Sperotto, R. Sadre, F. V. Vliet, and A. Pras, \"A labeled data set for flow-based intrusion detection,\" in Proc. IP Operations and Management (IPOM 2009), Lecture Notes in Computer Science, 2009, vol. 5843, pp 39-50.","DOI":"10.1007\/978-3-642-04968-2_4"},{"key":"ref17","doi-asserted-by":"publisher","unstructured":"[18] P. S. Bhattacharjee, A. K. M. Fujail, and S. A. Begum, \"A comparison of intrusion detection by K-Means and fuzzy c-means clustering algorithm over the NSL-KDD Dataset,\" in Proc. IEEE International Conference on Computational Intelligence and Computing Research, 2017, pp. 1-6.","DOI":"10.1109\/ICCIC.2017.8524401"},{"key":"ref18","doi-asserted-by":"publisher","unstructured":"[19] T. H. Hai, L. H. Hoang, and E. Huh, \"Network anomaly detection based on late fusion of several machine learning models,\" International Journal of Computer Network and Communications, 2020.","DOI":"10.5121\/ijcnc.2020.12608"},{"key":"ref19","doi-asserted-by":"publisher","unstructured":"[20] Y. Zhou, G. Cheng, S. Jiang, and M. Dai, \"Building an efficient intrusion detection system based on feature selection and ensemble classifier,\" arXiv e-prints, 2019.","DOI":"10.1016\/j.comnet.2020.107247"},{"key":"ref20","doi-asserted-by":"publisher","unstructured":"[21] Y. Xiao, J. Wu, Z. Lin, and X. Zhao, \"A deep learning-based multi-model ensemble method for cancer prediction,\" Computer Methods and Programs in Biomedicine, vol. 153, pp. 1-9, 2018.","DOI":"10.1016\/j.cmpb.2017.09.005"},{"key":"ref21","doi-asserted-by":"publisher","unstructured":"[22] T. H. Hai and N. T. Khiem, \"Architecture for IDS log processing using spark streaming,\" in Proc. 2nd International Conference on Electrical, Communication and Computer Engineering (ICECCE 2020), Istanbul, Turkey, 2020.","DOI":"10.1109\/ICECCE49384.2020.9179188"}],"container-title":["Journal of Communications"],"original-title":[],"link":[{"URL":"http:\/\/www.jocm.us\/uploadfile\/2021\/0720\/20210720030454657.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,25]],"date-time":"2021-11-25T06:32:00Z","timestamp":1637821920000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.jocm.us\/show-258-1679-1.html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":22,"URL":"https:\/\/doi.org\/10.12720\/jcm.16.8.347-354","relation":{},"ISSN":["2374-4367"],"issn-type":[{"type":"print","value":"2374-4367"}],"subject":[],"published":{"date-parts":[[2021]]}}}