{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:41:59Z","timestamp":1777657319989,"version":"3.51.4"},"reference-count":38,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2017,11,10]],"date-time":"2017-11-10T00:00:00Z","timestamp":1510272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Intrusion detection system (IDS) is a well-known and effective component of network security that provides transactions upon the network systems with security and safety. Most of earlier research has addressed difficulties such as overfitting, feature redundancy, high-dimensional features and a limited number of training samples but feature selection. We approach the problem of feature selection via sparse logistic regression (SPLR). In this paper, we propose a discriminative feature selection and intrusion classification based on SPLR for IDS. The SPLR is a recently developed technique for data analysis and processing via sparse regularized optimization that selects a small subset from the original feature variables to model the data for the purpose of classification. A linear SPLR model aims to select the discriminative features from the repository of datasets and learns the coefficients of the linear classifier. Compared with the feature selection approaches, like filter (ranking) and wrapper methods that separate the feature selection and classification problems, SPLR can combine feature selection and classification into a unified framework. The experiments in this correspondence demonstrate that the proposed method has better performance than most of the well-known techniques used for intrusion detection.<\/jats:p>","DOI":"10.3390\/fi9040081","type":"journal-article","created":{"date-parts":[[2017,11,10]],"date-time":"2017-11-10T11:12:26Z","timestamp":1510312346000},"page":"81","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":33,"title":["Network Intrusion Detection through Discriminative Feature Selection by Using Sparse Logistic Regression"],"prefix":"10.3390","volume":"9","author":[{"given":"Reehan","family":"Shah","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence, College of Computer Science, Zhejiang University, Hangzhou 310027, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuntao","family":"Qian","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, College of Computer Science, Zhejiang University, Hangzhou 310027, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dileep","family":"Kumar","sequence":"additional","affiliation":[{"name":"State Key Laboratory of ICT, College of Control Science and Engineering, Zhejiang University, Hangzhou 310027, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Munwar","family":"Ali","sequence":"additional","affiliation":[{"name":"COMSATS Institute of Information Technology, Lahore 54500, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad","family":"Alvi","sequence":"additional","affiliation":[{"name":"Department of Computer System engineering, The Islamia University of Bahawalpur, Bahawalpur 63100, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,11,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Kevric, J., Jukic, S., and Subasi, A. (2016). An effective combining classifier approach using tree algorithms for network intrusion detection. Neural Comput. Appl., 1\u20138.","DOI":"10.1007\/s00521-016-2418-1"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1016\/j.neucom.2013.04.038","article-title":"Effects-based feature identification for network intrusion detection","volume":"121","author":"Louvieris","year":"2013","journal-title":"Neurocomputing"},{"key":"ref_3","unstructured":"(2017, October 10). European Cybercrime Centre (EC3). Available online: https:\/\/www.europol.europa.eu\/activities-services\/main-reports\/internet-organised-crime-threat-assessment-iocta-2017."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"8609","DOI":"10.1016\/j.eswa.2015.07.015","article-title":"An intrusion detection system using network traffic profiling and online sequential extreme learning machine","volume":"42","author":"Singh","year":"2015","journal-title":"Expert Syst. Appl."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Natesan, P., and Rajesh, P. (2012, January 19\u201321). Cascaded classifier approach based on Adaboost to increase detection rate of rare network attack categories. Proceedings of the IEEE International Conference on Recent Trends In Information Technology (ICRTIT), Chennai, India.","DOI":"10.1109\/ICRTIT.2012.6206789"},{"key":"ref_6","unstructured":"Mohammadi, M., Raahemi, B., Akbari, A., and Nassersharif, B. (2011, January 17\u201319). Class dependent feature transformation for intrusion detection systems. Proceedings of the 19th IEEE Iranian Conference on Electrical Engineering, Tehran, Iran."},{"key":"ref_7","unstructured":"(2017, October 10). Snort Intrusion Detection System. Available online: http:\/\/www.snort.org."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"466","DOI":"10.1016\/j.cose.2009.01.001","article-title":"Building lightweight intrusion detection system using wrapper-based feature selection mechanisms","volume":"28","author":"Li","year":"2009","journal-title":"Comput. Secur."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1031","DOI":"10.1109\/JPROC.2010.2044470","article-title":"Sparse representation for computer vision and pattern recognition","volume":"98","author":"Wright","year":"2010","journal-title":"Proc. IEEE"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Hodo, E., Bellekens, X., Hamilton, A., Dubouilh, P., Iorkyase, E., Tachtatzis, C., and Atkinson, R. (2016, January 11\u201313). Threat analysis of iot networks using artificial neural network intrusion detection system. Proceedings of the IEEE International Symposium on Networks, Computers and Communications (ISNCC), Yasmine Hammamet, Tunisia.","DOI":"10.1109\/ISNCC.2016.7746067"},{"key":"ref_11","unstructured":"Hodo, E., Bellekens, X., Hamilton, A., Tachtatzis, C., and Atkinson, R. (2017). Shallow and Deep Networks Intrusion Detection System: A Taxonomy and Survey, Cornell University Library. arXiv preprint."},{"key":"ref_12","first-page":"368","article-title":"Intrusion detection and attack classifier based on three techniques: A comparative study","volume":"29","author":"Brifcani","year":"2011","journal-title":"Eng. Technol. J."},{"key":"ref_13","first-page":"148","article-title":"Intrusion Detection using Support Vector Machine with Feature Reduction Techniques","volume":"23","author":"Roopadevi","year":"2016","journal-title":"Indian J. Sci."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Zhang, J., and Zulkernine, M. (2006, January 20\u201322). A hybrid network intrusion detection technique using random forests. Proceedings of the IEEE First International Conference on Availability Reliability and Security (ARES'06), Vienna, Austria.","DOI":"10.1109\/ARES.2006.7"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1937","DOI":"10.1016\/j.eswa.2013.08.089","article-title":"Hybrid decision tree and na\u00efve Bayes classifiers for multi-class classification tasks","volume":"41","author":"Farid","year":"2014","journal-title":"Expert Syst. Appl."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"13492","DOI":"10.1016\/j.eswa.2012.07.009","article-title":"A network intrusion detection system based on a Hidden Na\u00efve Bayes multiclass classifier","volume":"39","author":"Koc","year":"2012","journal-title":"Expert Syst. Appl."},{"key":"ref_17","unstructured":"Farid, D.M., Harbi, N., and Rahman, M.Z. (2010). Combining Naive Bayes and Decision Tree for Adaptive Intrusion Detection, Cornell University Library. arXiv preprint."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"2040","DOI":"10.1016\/j.comnet.2013.04.005","article-title":"Toward an efficient and scalable feature selection approach for internet traffic classification","volume":"57","author":"Fahad","year":"2013","journal-title":"Comput. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1016\/j.kijoms.2015.07.002","article-title":"On the designing of two grains levels network intrusion detection system","volume":"1","author":"Jassim","year":"2015","journal-title":"Karbala Int. J. Mod. Sci."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"3088","DOI":"10.1016\/j.cor.2005.01.021","article-title":"Optimization-based feature selection with adaptive instance sampling","volume":"33","author":"Yang","year":"2006","journal-title":"Comput. Oper. Res."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"S\u00e1nchez-Maro\u00f1o, N., Alonso-Betanzos, A., and Calvo-Est\u00e9vez, R.M. (2009). A wrapper method for feature selection in multiple classes datasets. International Work-Conference on Artificial Neural Networks, Springer.","DOI":"10.1007\/978-3-642-02478-8_57"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Sani, R.A., and Ghasemi, A. (2015, January 3\u20135). Learning a new distance metric to improve an svm-clustering based intrusion detection system. Proceedings of the IEEE International Symposium on Artificial Intelligence and Signal Processing (AISP), Mashhad, Iran.","DOI":"10.1109\/AISP.2015.7123497"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"778","DOI":"10.1109\/TASLP.2014.2303296","article-title":"Application of deep belief networks for natural language understanding","volume":"22","author":"Sarikaya","year":"2014","journal-title":"IEEE\/ACM Trans. Audio Speech Lang. Process."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2276","DOI":"10.1109\/TGRS.2012.2209657","article-title":"Hyperspectral image classification based on structured sparse logistic regression and three-dimensional wavelet texture features","volume":"51","author":"Qian","year":"2013","journal-title":"IEEE Trans. Geosci. Remote Sens."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1111\/j.2517-6161.1996.tb02080.x","article-title":"Regression shrinkage and selection via the lasso","volume":"58","author":"Tibshirani","year":"1996","journal-title":"J. R. Stat. Soc."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Li, J., and Qian, Y. (2009, January 1\u20133). Regularized multinomial regression method for hyperspectral data classification via pathwise coordinate optimization. Proceedings of the IEEE Digital Image Computing: Techniques and Applications, DICTA\u201909, Melbourne, Australia.","DOI":"10.1109\/DICTA.2009.89"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Li, J., and Qian, Y. (2011, January 24\u201329). Dimension reduction of hyperspectral images with sparse linear discriminant analysis. Proceedings of the IEEE International Geoscience and Remote Sensing Symposium (IGARSS), Vancouver, BC, Canada.","DOI":"10.1109\/IGARSS.2011.6049828"},{"key":"ref_28","unstructured":"Liu, J., Chen, J., and Ye, J. (July, January 28). Large-scale sparse logistic regression. Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Paris, France."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the Second IEEE Symposium on Computational Intelligence for Security and Defence Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_30","first-page":"211","article-title":"Parallel Misuse and Anomaly Detection Model","volume":"14","author":"Goel","year":"2012","journal-title":"Int. J. Netw. Secur."},{"key":"ref_31","first-page":"101","article-title":"Network intrusion detection system using fuzzy logic","volume":"2","author":"Shanmugavadivu","year":"2011","journal-title":"Indian J. Comput. Sci. Eng."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1007\/s00778-006-0002-5","article-title":"A new intrusion detection system using support vector machines and hierarchical clustering","volume":"16","author":"Khan","year":"2007","journal-title":"VLDB J. Int. J. Very Large Data Bases"},{"key":"ref_33","first-page":"9","article-title":"Securing network traffic using genetically evolved transformations","volume":"19","author":"Faraoun","year":"2006","journal-title":"Malays. J. Comput. Sci."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Mukkamala, S., Sung, A.H., and Abraham, A. (2006). Intrusion detection systems using adaptive regression spines. Enterprise Information Systems VI, Springer.","DOI":"10.1007\/1-4020-3675-2_25"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"105","DOI":"10.3233\/JCS-2002-101-205","article-title":"Practical automated detection of stealthy portscans","volume":"10","author":"Staniford","year":"2002","journal-title":"J. Comput. Secur."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Yu, W.-Y., and Lee, H.-M. (2009). An incremental-learning method for supervised anomaly detection by cascading service classifier and ITI decision tree methods. Pacific-Asia Workshop on Intelligence and Security Informatics, Springer.","DOI":"10.1007\/978-3-642-01393-5_17"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Mazid, M.M., Ali, A.S., and Tickle, K.S. (2009, January 19\u201321). A comparison between rule based and association rule mining algorithms. Proceedings of the IEEE Third International Conference on Network and System Security, NSS\u201909, Gold Coast, Australia.","DOI":"10.1109\/NSS.2009.81"},{"key":"ref_38","unstructured":"Singh, S.P. (2010). Data Clustering Using K-Mean Algorithm for Network Intrusion Detection, Lovely Professional University."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/4\/81\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:48:59Z","timestamp":1760208539000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/4\/81"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11,10]]},"references-count":38,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2017,12]]}},"alternative-id":["fi9040081"],"URL":"https:\/\/doi.org\/10.3390\/fi9040081","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,11,10]]}}}