{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T04:05:38Z","timestamp":1779163538216,"version":"3.51.4"},"reference-count":27,"publisher":"MDPI AG","issue":"23","license":[{"start":{"date-parts":[[2021,11,25]],"date-time":"2021-11-25T00:00:00Z","timestamp":1637798400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>A reasonably good network intrusion detection system generally requires a high detection rate and a low false alarm rate in order to predict anomalies more accurately. Older datasets cannot capture the schema of a set of modern attacks; therefore, modelling based on these datasets lacked sufficient generalizability. This paper operates on the UNSW-NB15 Dataset, which is currently one of the best representatives of modern attacks and suggests various models. We discuss various models and conclude our discussion with the model that performs the best using various kinds of evaluation metrics. Alongside modelling, a comprehensive data analysis on the features of the dataset itself using our understanding of correlation, variance, and similar factors for a wider picture is done for better modelling. Furthermore, hypothetical ponderings are discussed for potential network intrusion detection systems, including suggestions on prospective modelling and dataset generation as well.<\/jats:p>","DOI":"10.3390\/s21237835","type":"journal-article","created":{"date-parts":[[2021,12,1]],"date-time":"2021-12-01T01:45:02Z","timestamp":1638323102000},"page":"7835","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Enhanced Network Intrusion Detection System"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2653-3780","authenticated-orcid":false,"given":"Ketan","family":"Kotecha","sequence":"first","affiliation":[{"name":"Symbiosis Centre for Applied Artificial Intelligence, Symbiosis International (Deemed University), Pune 412115, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7601-7800","authenticated-orcid":false,"given":"Raghav","family":"Verma","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prahalad V.","family":"Rao","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9150-3858","authenticated-orcid":false,"given":"Priyanshu","family":"Prasad","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vipul Kumar","family":"Mishra","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tapas","family":"Badal","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Divyansh","family":"Jain","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Deepak","family":"Garg","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shakti","family":"Sharma","sequence":"additional","affiliation":[{"name":"Department of CSE, Bennett University, Greater Noida 201310, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,11,25]]},"reference":[{"key":"ref_1","unstructured":"Alnaghes, M.S., and Gebali, F. (2015, January 26\u201328). A Survey on SomeCurrently Existing Intrusion Detection Systems for Mobile Ad Hoc Networks. Proceedings of the 2nd International Conference on Electrical and Electronics Engineering, Clean Energy and Green Computing (EEECEGC2015), Konya, Turkey."},{"key":"ref_2","unstructured":"Irwin, L. (2020, November 02). List of Data Breaches & Cyber Attacks in May 2020, IT Governance UK Blog, Available online: https:\/\/www.itgovernance.co.uk\/blog\/list-of-data-breaches-cyber-attacks-may-2020."},{"key":"ref_3","first-page":"225","article-title":"A network forensic scheme using correntropy-variation for attack detection","volume":"532","author":"Moustafa","year":"2018","journal-title":"IFIP Adv. Inf. Commun. Technol."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"32910","DOI":"10.1109\/ACCESS.2018.2844794","article-title":"A New Threat Intelligence Scheme for Safeguarding Industry 4.0 Systems","volume":"6","author":"Moustafa","year":"2018","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Al-Zewairi, M., Almajali, S., and Awajan, A. (2017, January 11\u201313). Experimental evaluation of a multi-layer feedforward artificial neural network classifier for network intrusion detection system. Proceedings of the 2017 International Conference on New Trends in Computing Sciences (ICTCS), Amman, Jordan.","DOI":"10.1109\/ICTCS.2017.29"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1007\/978-981-10-7871-2_13","article-title":"Anomaly detection system using beta mixture models and outlier detection","volume":"710","author":"Moustafa","year":"2018","journal-title":"Adv. Intell. Syst. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2909","DOI":"10.3233\/JIFS-169234","article-title":"PSI-NetVisor: Program semantic aware intrusion detection at network and hypervisor layer in cloud","volume":"32","author":"Mishra","year":"2017","journal-title":"J. Intell. Fuzzy Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1016\/j.knosys.2017.09.038","article-title":"Ramp loss k-support vector classification-regression; a robust and sparse multiclass approach to the intrusion detection problem","volume":"126","author":"Wang","year":"2017","journal-title":"Knowl.-Based Syst."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1007\/978-981-10-7871-2_3","article-title":"Flow aggregator module for analyzing network traffic","volume":"710","author":"Moustafa","year":"2018","journal-title":"Adv. Intell. Syst. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"481","DOI":"10.1109\/TBDATA.2017.2715166","article-title":"Novel Geometric Area Analysis Technique for Anomaly Detection Using Trapezoidal Area Estimation on Large-Scale Networks","volume":"5","author":"Moustafa","year":"2017","journal-title":"IEEE Trans. Big Data"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Moustafa, N., Creech, G., and Slay, J. (2017). Big Data Analytics for Intrusion Detection System: Statistical Decision-Making Using Finite Dirichlet Mixture Models. Data Analytics and Decision Support for Cybersecurity, Springer.","DOI":"10.1007\/978-3-319-59439-2_5"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1007\/978-3-319-90775-8_3","article-title":"Towards developing network forensic mechanism for botnet activities in the IoT based on machine learning techniques","volume":"Volume 235","author":"Koroniotis","year":"2018","journal-title":"Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Khan, M.A., and Kim, J. (2020). Toward developing efficient Conv-AE-based intrusion detection system using heterogeneous dataset. Electronics, 9.","DOI":"10.3390\/electronics9111771"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"101984","DOI":"10.1016\/j.cose.2020.101984","article-title":"SwiftIDS: Real-time intrusion detection system based on LightGBM and parallel intrusion detection mechanism","volume":"97","author":"Jin","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ferrag, M.A., Maglaras, L., Ahmim, A., Derdour, M., and Janicke, H. (2020). Rdtids: Rules and decision tree-based intrusion detection system for internet-of-things networks. Future Internet, 12.","DOI":"10.3390\/fi12030044"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS 2015), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_17","unstructured":"David, M.W. (2020, November 11). UNSW_NB15. Kaggle. Available online: https:\/\/www.kaggle.com\/mrwellsdavid\/unsw-nb15."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1080\/19393555.2015.1125974","article-title":"The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"2875","DOI":"10.3233\/JIFS-169230","article-title":"A multiclass cascade of artificial neural network for network intrusion detection","volume":"32","author":"Baig","year":"2017","journal-title":"J. Intell. Fuzzy Syst."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"So-In, C., Mongkonchai, N., Aimtongkham, P., Wijitsopon, K., and Rujirakul, K. (2014, January 6\u20138). An evaluation of data mining classification models for network intrusion detection. Proceedings of the 2014 Fourth International Conference on Digital Information and Communication Technology and its Applications (DICTAP), Bangkok, Thailand.","DOI":"10.1109\/DICTAP.2014.6821663"},{"key":"ref_21","first-page":"1015","article-title":"Beyond accuracy, F-score and ROC: A family of discriminant measures for performance evaluation","volume":"Volume 4304","author":"Sokolova","year":"2006","journal-title":"AI 2006: Advances in Artificial Intelligence"},{"key":"ref_22","unstructured":"Tuzlukov, V.P. (2013). Signal Detection Theory, Springer Science & Business Media."},{"key":"ref_23","unstructured":"Klambauer, G., Unterthiner, T., Mayr, A., and Hochreiter, S. (2017, January 4\u20139). Self-normalizing neural networks. Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_24","unstructured":"Rubinstein, R.Y., and Kroese, D.P. (2004). The Cross-Entropy Method: A Unified Approach to Combinatorial Optimization, Monte-Carlo Simulation, and Machine Learning, Springer."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Chen, T., and Guestrin, C. (2016, January 13\u201317). XGBoost: A scalable tree boosting system. Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"349","DOI":"10.4310\/SII.2009.v2.n3.a8","article-title":"Multiclass AdaBoost","volume":"2","author":"Hastie","year":"2009","journal-title":"Stat. Interface"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1137\/S1052623497318992","article-title":"A Nonlinear Conjugate Gradient Method with a Strong Global Convergence Property","volume":"10","author":"Dai","year":"1999","journal-title":"SIAM J. Optim."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/23\/7835\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:35:34Z","timestamp":1760168134000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/23\/7835"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,25]]},"references-count":27,"journal-issue":{"issue":"23","published-online":{"date-parts":[[2021,12]]}},"alternative-id":["s21237835"],"URL":"https:\/\/doi.org\/10.3390\/s21237835","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,25]]}}}