{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T20:33:03Z","timestamp":1782937983526,"version":"3.54.5"},"reference-count":46,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2022,6,27]],"date-time":"2022-06-27T00:00:00Z","timestamp":1656288000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Key R&amp;D and promotion projects of Henan Province (Technological research)","award":["212102210143"],"award-info":[{"award-number":["212102210143"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>The mass of redundant and irrelevant data in network traffic brings serious challenges to intrusion detection, and feature selection can effectively remove meaningless information from the data. Most current filtered and embedded feature selection methods use a fixed threshold or ratio to determine the number of features in a subset, which requires a priori knowledge. In contrast, wrapped feature selection methods are computationally complex and time-consuming; meanwhile, individual feature selection methods have a bias in evaluating features. This work designs an ensemble-based automatic feature selection method called EAFS. Firstly, we calculate the feature importance or ranks based on individual methods, then add features to subsets sequentially by importance and evaluate subset performance comprehensively by designing an NSOM to obtain the subset with the largest NSOM value. When searching for a subset, the subset with higher accuracy is retained to lower the computational complexity by calculating the accuracy when the full set of features is used. Finally, the obtained subsets are ensembled, and by comparing the experimental results on three large-scale public datasets, the method described in this study can help in the classification, and also compared with other methods, we discover that our method outperforms other recent methods in terms of performance.<\/jats:p>","DOI":"10.3390\/info13070314","type":"journal-article","created":{"date-parts":[[2022,6,27]],"date-time":"2022-06-27T22:31:14Z","timestamp":1656369074000},"page":"314","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":34,"title":["An Effective Ensemble Automatic Feature Selection Method for Network Intrusion Detection"],"prefix":"10.3390","volume":"13","author":[{"given":"Yang","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450001, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3485-8470","authenticated-orcid":false,"given":"Hongpo","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450001, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450001, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,27]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1007\/s10922-021-09615-7","article-title":"Towards model generalization for intrusion detection: Unsupervised machine learning techniques","volume":"30","author":"Verkerken","year":"2021","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1016\/j.ijinfomgt.2018.08.006","article-title":"Real-time big data processing for anomaly detection: A Survey","volume":"45","author":"Habeeb","year":"2019","journal-title":"Int. J. Inf. Manag."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kabir, M., and Hartmann, S. (2018, January 4). Cyber security challenges: An efficient intrusion detection system design. Proceedings of the 2018 International Young Engineers Forum (YEF-ECE), Costa da Caparica, Portugal.","DOI":"10.1109\/YEF-ECE.2018.8368933"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2015","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.jocs.2017.03.006","article-title":"Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model","volume":"25","author":"Aljawarneh","year":"2018","journal-title":"J. Comput. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"116822","DOI":"10.1016\/j.eswa.2022.116822","article-title":"A review of recent approaches on wrapper feature selection for intrusion detection","volume":"198","author":"Maldonado","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1007\/s11235-018-0475-8","article-title":"A comprehensive survey on network anomaly detection","volume":"70","author":"Fernandes","year":"2019","journal-title":"Telecommun. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1007\/s10462-021-10037-9","article-title":"A survey on intrusion detection system: Feature selection, model, performance measures, application perspective, challenges, and future research directions","volume":"55","author":"Thakkar","year":"2021","journal-title":"Artif. Intell. Rev."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"106337","DOI":"10.1016\/j.asoc.2020.106337","article-title":"A novel hybrid feature selection method based on dynamic feature importance","volume":"93","author":"Wei","year":"2020","journal-title":"Appl. Soft. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"104216","DOI":"10.1016\/j.engappai.2021.104216","article-title":"Supervised feature selection techniques in network intrusion detection: A critical review","volume":"101","author":"Galatro","year":"2021","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_11","first-page":"907","article-title":"A review of unsupervised feature selection methods","volume":"53","year":"2019","journal-title":"Artif. Intell. Rev."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"101752","DOI":"10.1016\/j.cose.2020.101752","article-title":"A deep learning method with wrapper based feature extraction for wireless intrusion detection system","volume":"92","author":"Kasongo","year":"2020","journal-title":"Comput. Secur"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"105745","DOI":"10.1016\/j.knosys.2020.105745","article-title":"An information theoretic approach to quantify the stability of feature selection and ranking algorithms","volume":"195","author":"Parnell","year":"2020","journal-title":"Knowl.-Based Syst"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1249","DOI":"10.1007\/s12652-020-02167-9","article-title":"Attack classification using feature selection techniques: A comparative study","volume":"12","author":"Thakkar","year":"2020","journal-title":"J. Amb. Intell. Hum. Comp."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"350","DOI":"10.1016\/j.eswa.2018.11.006","article-title":"Embedded feature selection accounting for unknown data heterogeneity","volume":"119","author":"Lu","year":"2019","journal-title":"Expert Syst. Appl."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"106097","DOI":"10.1016\/j.knosys.2020.106097","article-title":"Ensemble feature selection in high dimension, low sample size datasets: Parallel and serial combination approaches","volume":"203","author":"Tsai","year":"2020","journal-title":"Knowl.-Based Syst."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"31","DOI":"10.4018\/IJISP.201907010102","article-title":"Building an effective approach toward intrusion detection using ensemble feature selection","volume":"13","author":"Shukla","year":"2019","journal-title":"Int. Inf. Secur. Priv."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1761","DOI":"10.1007\/s10586-020-03222-y","article-title":"Efficient feature selection and classification through ensemble method for network intrusion detection on cloud computing","volume":"24","author":"Krishnaveni","year":"2021","journal-title":"Clust. Comput."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.inffus.2018.11.008","article-title":"Ensembles for feature selection: A review and future trends","volume":"52","year":"2019","journal-title":"Inf. Fusion"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1186\/s13638-016-0623-3","article-title":"Ensemble-based multi-filter feature selection method for DDoS detection in cloud computing","volume":"2016","author":"Osanaiye","year":"2016","journal-title":"EURASIP J. Wirel. Commun. Netw."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"106495","DOI":"10.1109\/ACCESS.2019.2929487","article-title":"Identifying and benchmarking key features for cyber intrusion detection: An ensemble approach","volume":"7","author":"Binbusayyis","year":"2019","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"114765","DOI":"10.1016\/j.eswa.2021.114765","article-title":"Feature selection for classification using principal component analysis and information gain","volume":"174","year":"2021","journal-title":"Expert Syst. Appl."},{"key":"ref_23","first-page":"1157","article-title":"An introduction to variable and feature selection","volume":"3","author":"Guyon","year":"2003","journal-title":"J. Mach. Learn. Res."},{"key":"ref_24","unstructured":"Singh, M., Gupta, P., Tyagi, V., Flusser, J., and \u00d6ren, T. (2018). Extreme gradient boosting based tuning for classification in intrusion detection systems. Advances in Computing and Data Sciences, Springer."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Fitni, Q.R.S., and Ramli, K. (2020, January 7\u20138). Implementation of ensemble learning and feature selection for performance improvements in anomaly-based intrusion detection systems. Proceedings of the 2020 IEEE International Conference on Industry 4.0, Artificial Intelligence, and Communications Technology (IAICT), Bali, Indonesia.","DOI":"10.1109\/IAICT50021.2020.9172014"},{"key":"ref_26","unstructured":"Da Silva, D., Wang, Q., and Zhang, L.J. (2019). Dynamic betwork anomaly detection system by using deep learning techniques. Advances in Computing and Data Sciences, Springer."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.cose.2017.06.005","article-title":"A GA-LR wrapper approach for feature selection in network intrusion detection","volume":"70","author":"Khammassi","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"107247","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"102164","DOI":"10.1016\/j.cose.2020.102164","article-title":"A novel combinatorial optimization based feature selection method for network intrusion detection","volume":"102","author":"Nazir","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"8875404","DOI":"10.1155\/2020\/8875404","article-title":"Feature selection based on cross-correlation for the intrusion detection system","volume":"2020","author":"Farahani","year":"2020","journal-title":"Secur. Commun. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1007\/s12065-019-00199-5","article-title":"A new evolutionary neural networks based on intrusion detection systems using locust swarm optimization","volume":"12","author":"Benmessahel","year":"2019","journal-title":"Evol. Intell."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"304","DOI":"10.1016\/j.cose.2018.04.010","article-title":"Intrusion detection system for wireless mesh network using multiple support vector machine classifiers with genetic-algorithm-based feature selection","volume":"77","author":"Vijayanand","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1016\/j.eswa.2017.07.005","article-title":"A feature reduced intrusion detection system using ANN classifier","volume":"88","author":"Akashdeep","year":"2017","journal-title":"Expert Syst. Appl."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1016\/j.cose.2018.11.005","article-title":"Firefly algorithm based feature selection for network intrusion detection","volume":"81","author":"Selvakumar","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1007\/s12652-021-02907-5","article-title":"A feature reduction based reflected and exploited DDoS attacks detection system","volume":"13","author":"Kshirsagar","year":"2022","journal-title":"J. Ambient Intell. Hum. Comput."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"4237","DOI":"10.3233\/JIFS-200850","article-title":"An intelligent flow-based and signature-based IDS for SDNs using ensemble feature selection and a multi-layer machine learning-based classifier","volume":"40","author":"Deepalakshmi","year":"2021","journal-title":"J. Intell. Fuzzy Syst."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Bhatia, M.P.S., and Sangwan, S.R. (2021). Soft computing for anomaly detection and prediction to mitigate IoT-based real-time abuse. Pers. Ubiquit. Comput., 1\u201311.","DOI":"10.1007\/s00779-021-01567-8"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1080\/19393555.2020.1767240","article-title":"Network intrusion detection based on deep learning model optimized with rule-based hybrid feature selection","volume":"29","author":"Ayo","year":"2021","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Karna, I., Madam, A., Deokule, C., Adhao, R., and Pachghare, V. (2021, January 2\u20134). Ensemble-based filter feature selection technique for building flow-based IDS. Proceedings of the 2021 2nd International Conference on Advances in Computing, Communication, Embedded and Secure Systems (ACCESS), Ernakulam, India.","DOI":"10.1109\/ACCESS51619.2021.9563297"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"107251","DOI":"10.1016\/j.comnet.2020.107251","article-title":"An effect of chaos grasshopper optimization algorithm for protection of network infrastructure","volume":"176","author":"Dwivedi","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1186\/s40537-021-00426-w","article-title":"Detecting cybersecurity attacks across different network features and learners","volume":"8","author":"Leevy","year":"2021","journal-title":"J. Big Data"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_43","unstructured":"Ghorbani, A.A., Habibi Lashkari, A., and Sharafaldin, I. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP), Madeira, Portugal."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1016\/j.comnet.2018.11.010","article-title":"Dimensionality reduction with IG-PCA and ensemble classifier for network intrusion detection","volume":"148","author":"Salo","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"2735","DOI":"10.1007\/s10489-018-01408-x","article-title":"A new hybrid approach for intrusion detection using machine learning methods","volume":"49","year":"2019","journal-title":"Appl. Intell."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Vaca, F.D., and Niyaz, Q. (2018, January 1\u20133). An Ensemble Learning Based Wi-Fi Network Intrusion Detection System (WNIDS). Proceedings of the 2018 IEEE 17th International Symposium on Network Computing and Applications (NCA), Cambridge, MA, USA.","DOI":"10.1109\/NCA.2018.8548315"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/13\/7\/314\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:39:02Z","timestamp":1760139542000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/13\/7\/314"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,27]]},"references-count":46,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2022,7]]}},"alternative-id":["info13070314"],"URL":"https:\/\/doi.org\/10.3390\/info13070314","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,27]]}}}