{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T10:14:34Z","timestamp":1785233674207,"version":"3.55.0"},"reference-count":57,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2020,4,30]],"date-time":"2020-04-30T00:00:00Z","timestamp":1588204800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The pursuit to spot abnormal behaviors in and out of a network system is what led to a system known as intrusion detection systems for soft computing besides many researchers have applied machine learning around this area. Obviously, a single classifier alone in the classifications seems impossible to control network intruders. This limitation is what led us to perform dimensionality reduction by means of correlation-based feature selection approach (CFS approach) in addition to a refined ensemble model. The paper aims to improve the Intrusion Detection System (IDS) by proposing a CFS + Ensemble Classifiers (Bagging and Adaboost) which has high accuracy, high packet detection rate, and low false alarm rate. Machine Learning Ensemble Models with base classifiers (J48, Random Forest, and Reptree) were built. Binary classification, as well as Multiclass classification for KDD99 and NSLKDD datasets, was done while all the attacks were named as an anomaly and normal traffic. Class labels consisted of five major attacks, namely Denial of Service (DoS), Probe, User-to-Root (U2R), Root to Local attacks (R2L), and Normal class attacks. Results from the experiment showed that our proposed model produces 0 false alarm rate (FAR) and 99.90% detection rate (DR) for the KDD99 dataset, and 0.5% FAR and 98.60% DR for NSLKDD dataset when working with 6 and 13 selected features.<\/jats:p>","DOI":"10.3390\/s20092559","type":"journal-article","created":{"date-parts":[[2020,5,4]],"date-time":"2020-05-04T14:00:43Z","timestamp":1588600843000},"page":"2559","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":121,"title":["The Use of Ensemble Models for Multiple Class and Binary Class Classification for Improving Intrusion Detection Systems"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4350-3911","authenticated-orcid":false,"given":"Celestine","family":"Iwendi","sequence":"first","affiliation":[{"name":"Department of Electronics, BCC of Central South University of Forestry and Tech, Changsha 410004, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Suleman","family":"Khan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Air University, Islamabad 44000, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1199-7446","authenticated-orcid":false,"given":"Joseph Henry","family":"Anajemba","sequence":"additional","affiliation":[{"name":"Department of Communication Engineering, Hohai University, Changzhou 211100, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0878-4615","authenticated-orcid":false,"given":"Mohit","family":"Mittal","sequence":"additional","affiliation":[{"name":"Department of Information Science and Engineering, Kyoto Sangyo University, Kyoto 603-8555, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6852-1206","authenticated-orcid":false,"given":"Mamdouh","family":"Alenezi","sequence":"additional","affiliation":[{"name":"College of Computer and Information Sciences, Prince Sultan University, Riyadh 12435, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1928-3704","authenticated-orcid":false,"given":"Mamoun","family":"Alazab","sequence":"additional","affiliation":[{"name":"College of Engineering, IT and Environment, Charles Darwin University, Casuarina NT 0800, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,4,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1186\/s13635-019-0098-y","article-title":"Multi-layer intrusion detection system with ExtraTrees feature selection, extreme learning machine ensemble, and softmax aggregation","volume":"2019","author":"Sharma","year":"2019","journal-title":"Eur. J. Inf. Secur."},{"key":"ref_2","first-page":"14","article-title":"Design and Implementation of Multi-model Biomatrix Identification System","volume":"99","author":"Omran","year":"2014","journal-title":"Int. J. Comput. Appl."},{"key":"ref_3","first-page":"192","article-title":"A Hybrid Ensemble Method for Multi class Classification and Outlier Detection","volume":"45","author":"Kaimuru","year":"2019","journal-title":"Int. J. Sci. Basic Appl. Res."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1016\/j.procs.2016.06.047","article-title":"random forest Modeling for Network Intrusion Detection System","volume":"89","author":"Farnaaz","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2741","DOI":"10.1002\/sec.592","article-title":"Hybrid intelligent systems for detecting network intrusions","volume":"8","author":"Panda","year":"2015","journal-title":"Secur. Commun. Netw."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"e3547","DOI":"10.1002\/dac.3547","article-title":"An intrusion detection system based on combining probability predictions of a tree of classifiers","volume":"31","author":"Ahmim","year":"2018","journal-title":"Int. J. Commun. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Ma, T., Wang, F., Cheng, J., Yu, Y., and Chen, X. (2016). A Hybrid Spectral Clustering and Deep Neural Network Ensemble Algorithm for Intrusion Detection in Sensor Networks. Sensors, 16.","DOI":"10.3390\/s16101701"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.jocs.2017.03.006","article-title":"Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model","volume":"25","author":"Aljawarneh","year":"2018","journal-title":"J. Comput. Sci."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Khonde, S.R., and Ulagamuthalvi, V. (2019). Ensemble-based semi-supervised learning approach for a distributed intrusion detection system. J. Cyber Secur. Technol.","DOI":"10.1080\/23742917.2019.1623475"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Yang, Y., Zheng, K., Wu, C., and Yang, Y. (2019). Improving the Classification Effectiveness of Intrusion Detection by using Improved Conditional Variational AutoEncoder and Deep Neural Network. Sensors, 19.","DOI":"10.3390\/s19112528"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Thing, V.L.L. (2017, January 19\u201322). IEEE 802.11 Network Anomaly Detection and Attack Classification: A Deep Learning Approach. Proceedings of the IEEE Wireless Communications and Networking Conference, San Francisco, CA, USA.","DOI":"10.1109\/WCNC.2017.7925567"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1527","DOI":"10.1162\/neco.2006.18.7.1527","article-title":"A fast learning algorithm for deep belief nets","volume":"18","author":"Hinton","year":"2006","journal-title":"Neural Comput."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"5947","DOI":"10.4249\/scholarpedia.5947","article-title":"Deep belief networks","volume":"4","author":"Hinton","year":"2009","journal-title":"Scholarpedia"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2986","DOI":"10.1109\/TC.2016.2519914","article-title":"Building an intrusion detection system using a filter-based feature selection algorithm","volume":"65","author":"Ambusaidi","year":"2016","journal-title":"IEEE Trans. Comput."},{"key":"ref_15","unstructured":"UNB (2018, December 10). NSL-KDD Dataset. Available online: https:\/\/www.unb.ca\/cic\/datasets\/nsl.html."},{"key":"ref_16","first-page":"446","article-title":"A study on NSL-KDD dataset for intrusion detection system based on classification algorithms","volume":"4","author":"Dhanabal","year":"2015","journal-title":"Int. J. Adv. Res. Comput. Commun. Eng."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"28462","DOI":"10.1109\/ACCESS.2020.2968537","article-title":"Realizing an Efficient IoMT-Assisted Patient Diet Recommendation System Through Machine Learning Model","volume":"8","author":"Iwendi","year":"2020","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Lopez-Martin, M., Carro, B., Sanchez-Esguevillas, A., and Lloret, J. (2017). Conditional Variational Autoencoder for Prediction and Feature Recovery Applied to Intrusion Detection in IoT. Sensors, 17.","DOI":"10.3390\/s17091967"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"53931","DOI":"10.1109\/ACCESS.2020.2980196","article-title":"Optimal Cooperative Offloading Scheme for Energy Efficient Multi-Access Edge Computation","volume":"8","author":"Anajemba","year":"2020","journal-title":"IEEE Access"},{"key":"ref_20","first-page":"541","article-title":"Anomaly network-based intrusion detection system using a reliable hybrid artificial bee colony and Adaboost algorithms","volume":"31","author":"Mazini","year":"2019","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ren, J., Guo, J., Wang, Q., Huang, Y., Hao, X., and Hu, J. (2019). Building an Effective Intrusion Detection System by using Hybrid Data Optimization Based on Machine Learning Algorithms. Secur. Commun. Netw.","DOI":"10.1155\/2019\/7130868"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"4062","DOI":"10.1016\/j.eswa.2014.12.040","article-title":"MARK-ELM: Application of a novel Multiple Kernel Learning framework for improving the robustness of Network Intrusion Detection","volume":"42","author":"Fossaceca","year":"2015","journal-title":"Expert Syst. Appl."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"5947","DOI":"10.1016\/j.eswa.2010.11.028","article-title":"Feature selection and classification in multiple class datasets: An application to KDD Cup 99 dataset","volume":"38","year":"2011","journal-title":"Expert Syst. Appl."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kim, J., Thu, H.L.T., and Kim, H. (2016, January 15\u201317). Long Short Term Memory Recurrent Neural Network Classifier for Intrusion Detection. Proceedings of the International Conference on Platform Technology and Service (PlatCon, 2016), Jeju, Korea.","DOI":"10.1109\/PlatCon.2016.7456805"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1078","DOI":"10.1109\/TCYB.2015.2423295","article-title":"Binarization with boosting and oversampling for multiclass classification","volume":"46","author":"Sen","year":"2016","journal-title":"IEEE Trans. Cybern."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Dong, L., Frank, E., and Kramer, S. (2005, January 3\u20137). Ensembles of balanced nested dichotomies for multi-class problems. Proceedings of the European Conference on Principles of Data Mining and Knowledge Discovery, Porto, Portugal.","DOI":"10.1007\/11564126_13"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"624","DOI":"10.1109\/TKDE.2008.181","article-title":"Adapted one-versus-all decision trees for data stream classification","volume":"21","author":"Hashemi","year":"2009","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_28","first-page":"1","article-title":"One versus all classification in network intrusion detection using decision tree","volume":"2","author":"Gaikwad","year":"2012","journal-title":"Int. J. Sci. Res. Publ."},{"key":"ref_29","unstructured":"Govindarajan, M., and Chandrasekaran, R. (2012, January 24\u201326). Intrusion detection using an ensemble of classification methods. Proceedings of the World Congress on Engineering and Computer Science, San Francisco, CA, USA."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"306","DOI":"10.1016\/j.eswa.2010.06.066","article-title":"A novel intrusion detection system based on hierarchical clustering and support vector machines","volume":"38","author":"Horng","year":"2011","journal-title":"Expert Syst. Appl."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1016\/j.ins.2017.06.007","article-title":"A novel weighted support vector machines multiclass classifier based on differential evolution for intrusion detection systems","volume":"414","author":"Aburomman","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_32","first-page":"462","article-title":"Intrusion detection model using fusion of chi-square feature selection and multi class SVM","volume":"29","author":"Thaseen","year":"2017","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"ref_33","first-page":"1","article-title":"Smart Security Implementation for Wireless Sensor Network Nodes","volume":"1","author":"Iwendi","year":"2015","journal-title":"J. Wirel. Sens. Netw."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Mittal, M., Saraswat, L.K., Iwendi, C., and Anajemba, J.H. (2019, January 18\u201319). A Neuro-Fuzzy Approach for Intrusion Detection in Energy Efficient Sensor Routing. Proceedings of the 4th International Conference on Internet of Things: Smart Innovation and Usages (IoT-SIU), Ghaziabad, India.","DOI":"10.1109\/IoT-SIU.2019.8777501"},{"key":"ref_35","first-page":"1","article-title":"Enhanced security technique for wireless sensor network nodes, Wireless Sensor Systems (WSS 2012)","volume":"2","author":"Iwendi","year":"2012","journal-title":"IET Conf."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"47258","DOI":"10.1109\/ACCESS.2018.2864111","article-title":"On Detection of Sybil Attack in Large-Scale VANETs using Spider-Monkey Technique","volume":"6","author":"Iwendi","year":"2018","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Iwendi, C., Suresh, P., Revathi, M., Srinivasan, K., and Chang, C.-Y. (2019). An Efficient and Unique TF\/IDF Algorithmic Model-Based Data Analysis for Handling Applications with Big Data Streaming, published in Artificial Intelligence- Applications and Methodologies of Artificial Intelligence in Big Data Analysis. Electronics, 8.","DOI":"10.3390\/electronics8111331"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"e3627","DOI":"10.1002\/ett.3627","article-title":"An Optimal Multi-tier Resource Allocation of Cloud RAN in 5G using Machine Learning","volume":"30","author":"Bashir","year":"2019","journal-title":"Trans. Emerg. Telecommun. Technol. Wiley"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"4867","DOI":"10.1007\/s11227-018-2263-3","article-title":"A Machine Learning Approach for Feature Selection Traffic Classification using Security Analysis","volume":"76","author":"Shafiq","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_40","unstructured":"Kayacik, H.G., Zincir-Heywood, A.N., and Heywood, M.I. (2005, January 12\u201314). Selecting features for intrusion detection: A feature relevance analysis on KDD 99 benchmark. Proceedings of the Third Annual Conference on Privacy, Security and Trust, St. Andrews, NB, Canada."},{"key":"ref_41","first-page":"25","article-title":"Intrusion Detection in kdd99 Dataset using SVM-PSO and Feature Reduction with Information Gain","volume":"98","author":"Saxena","year":"2014","journal-title":"Int. J. Comput. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Mittal, M., and Kumar, K. (2016, January 29\u201330). Data Clustering in Wireless Sensor Network Implemented On Self Organization Feature Map (SOFM) Neural Network. Proceedings of the IEEE International Conference on Computing Communication and Automation(ICCCA), Noida, India.","DOI":"10.1109\/CCAA.2016.7813718"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Mittal, M., and Kumar, K. (2014, January 14\u201316). Network Lifetime Enhancement of Homogeneous Sensor Network using ART1 Neural Network. Proceedings of the Sixth International Conference on Computational Intelligence and Communication Networks, Bhopal, India.","DOI":"10.1109\/CICN.2014.110"},{"key":"ref_44","first-page":"28","article-title":"Quality of Services Provisioning in Wireless Sensor Networks using Artificial Neural Network: A Survey","volume":"117","author":"Mittal","year":"2015","journal-title":"Int. J. Comput. Appl."},{"key":"ref_45","unstructured":"Hall, M.A. (1999). Correlation-Based Feature Selection for Machine Learning, University of Waikato."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Wosiak, A., and Zakrzewska, D. (2018). Integrating correlation-based feature selection and clustering for improved cardiovascular disease diagnosis. Complexity.","DOI":"10.1155\/2018\/2520706"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"627","DOI":"10.1007\/s00500-019-04453-x","article-title":"Improvement in Hadoop performance using integrated feature extraction and machine learning algorithms","volume":"24","author":"Sarumathiy","year":"2020","journal-title":"Soft Comput."},{"key":"ref_48","unstructured":"(2019, December 30). Accuracy, Precision, Recall F1-Score: Interpretation of Performance Measures-Exsilio Blog. Available online: https:\/\/blog.exsilio.com\/all\/accuracy-precision-recall-F1-score-interpretation-of-performance-measures\/."},{"key":"ref_49","unstructured":"(2019, November 24). Weka 3-Data Mining with Open Source Machine Learning Software in Java. Available online: https:\/\/www.cs.waikato.ac.nz\/ml\/weka\/."},{"key":"ref_50","unstructured":"(2019, December 26). KDD Cup 1999 Data. Available online: http:\/\/kdd.ics.uci.edu\/datasets\/kddcup99\/kddcup99.html."},{"key":"ref_51","unstructured":"(2019, December 26). NSL-KDD|Datasets|Research|Canadian Institute for Cybersecurity|UNB. Available online: https:\/\/www.unb.ca\/cic\/datasets\/nsl.html."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"185","DOI":"10.1007\/978-3-319-30933-0_20","article-title":"DAREnsemble: Decision tree and rule learner based ensemble for network intrusion detection system","volume":"50","author":"Gaikwad","year":"2016","journal-title":"Smart Innov. Syst. Technol."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1007\/s10844-015-0388-x","article-title":"Two-tier network anomaly detection model: A machine learning approach","volume":"48","author":"Pajouh","year":"2017","journal-title":"J. Intell. Inf. Syst."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Pervez, M.S., and Farid, D.M. (2014, January 18\u201320). Feature Selection and Intrusion Classification in NSL-KDD cup 99 Dataset employing SVMs. Proceedings of the 8th International Conference on Software, Knowledge, Information Management and Applications (SKIMA 2014), Dhaka, Bangladesh.","DOI":"10.1109\/SKIMA.2014.7083539"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1007\/978-81-322-2695-6_45","article-title":"Improving the accuracy of intrusion detection using gar-forest with feature selection","volume":"404","author":"Kanakarajan","year":"2016","journal-title":"Adv. Intell. Syst. Comput."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Pham, N.T., Foo, E., Suriadi, S., Jeffrey, H., and Lahza, H.F.M. (2018). Improving performance of intrusion detection system using ensemble methods and feature selection. ACM.","DOI":"10.1145\/3167918.3167951"},{"key":"ref_57","first-page":"806954","article-title":"Feature Selection using Particle Swarm Optimization in Intrusion Detection","volume":"11","author":"Ahmad","year":"2015","journal-title":"Int. J. Distrib. Sens. Netw."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/9\/2559\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T13:52:11Z","timestamp":1760363531000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/9\/2559"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,4,30]]},"references-count":57,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2020,5]]}},"alternative-id":["s20092559"],"URL":"https:\/\/doi.org\/10.3390\/s20092559","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,4,30]]}}}