A Theoretical Analysis of Feature Selection Methods in Machine Learning-Based Intrusion Detection Systems

Main Article Content

Junlin Yao

Keywords

intrusion detection system (IDS), machine learning, feature selection, cybersecurity, anomaly detection

Abstract

With the increasing complexity of the network environment, more and more machine learning-based Intrusion Detection Systems (IDS) are now being applied to identify unusual behaviour in network traffic. Many Dimensions and excess Redundancy reduce Detection Accuracy and Computation Efficiency. Therefore, to enhance the generalisation power of the model, feature selection can be employed. This paper offers theoretical research on feature selection for machine learning-based intrusion detection systems. Systematically review the traditional machine learning algorithms of Support Vector Machines (SVM), Decision Trees, Random Forests, etc., and explore their applications in intrusion detection. The three categories of feature selection are shown in more detail below: filter methods, wrapper methods and embedded methods. The change in detection accuracy and false-positive rate, as well as computational efficiency and model stability, are all related to feature selection. The study shows that feature selection plays a critical role in improving intrusion detection performance by reducing dimensionality, eliminating redundant features, and enhancing model generalization. The aim of this paper is to provide comprehensive theoretical support for the investigation of cooperation between feature selection methods and machine learning models in intrusion detection systems, and to offer a new reference for future research on high-efficiency and intelligent cybersecurity solutions.

Abstract 8 | PDF Downloads 3

References

  • [1] Dhingra, S., Madda, R. B., Patan, R., Jiao, P., Barri, K., & Alavi, A. H. (2021). Internet of things-based fog and cloud computing technology for smart traffic monitoring. Internet of Things, 14, 100175.
  • [2] Abdulganiyu, O. H., Ait Tchakoucht, T., & Saheed, Y. K. (2023). A systematic literature review for network intrusion detection system (IDS). International journal of information security, 22(5), 1125.
  • [3] Almotairi, A., Atawneh, S., Khashan, O. A., & Khafajah, N. M. (2024). Enhancing intrusion detection in IoT networks using machine learning-based feature selection and ensemble models. Systems Science & Control Engineering, 12.
  • [4] Boateng, E. Y., Otoo, J., & Abaye, D. A. (2020). Basic tenets of classification algorithms K-nearest- neighbor, support vector machine, random forest and neural network: A review. Journal of Data Analysis and Information Processing, 8(4), 341-357.
  • [5] Xu, D., Lv, Y., Wang, M., Zheng, B., Zhao, J., & Yu, J. (2025). Demgan: a machine learning-based intrusion detection system evasion scheme. Computers, Materials, & Continua, 84(1), 1731.
  • [6] Chen, C. W., Tsai, Y. H., Chang, F. R., & Lin, W. C. (2020). Ensemble feature selection in medical datasets: Combining filter, wrapper, and embedded feature selection results. expert systems, 37(5), e12553.
  • [7] Doğan, Ü., Glasmachers, T., & Igel, C. (2016). A unified view on multi-class support vector classification. Journal of Machine Learning Research, 17(45), 1-32.
  • [8] Saheed, Y. K., & Hambali, M. A. (2021, October). Customer churn prediction in telecom sector with machine learning and information gain filter feature selection algorithms. In 2021 International Conference on Data Analytics for Business and Industry (ICDABI) (pp. 208-213). IEEE.
  • [9] Nnamoko, N., Arshad, F., England, D., Vora, J., & Norman, J. (2014). Evaluation of filter and wrapper methods for feature selection in supervised machine learning. Age, 21(81), 33-2.
  • [10] Bashir, S., Khattak, I. U., Khan, A., Khan, F. H., Gani, A., & Shiraz, M. (2022). A novel feature selection method for classification of medical data using filters, wrappers, and embedded approaches. Complexity, 2022(1), 8190814.
  • [11] Ngo, V. D., Vuong, T. C., Van Luong, T., & Tran, H. (2024). Machine learning-based intrusion detection: feature selection versus feature extraction. Cluster Computing, 27(3), 2365-2379.
  • [12] Ali, M. H., Jaber, M. M., Abd, S. K., Rehman, A., Awan, M. J., Damaševičius, R., & Bahaj, S. A. (2022). Threat analysis and distributed denial of service (DDoS) attack recognition in the internet of things (IoT). Electronics, 11(3), 494.
  • [13] Shehadeh, A., ALTaweel, H., & Qusef, A. (2023, December). Analysis of data mining techniques on KDD-Cup'99, NSL-KDD and UNSW-NB15 datasets for intrusion detection. In 2023 24th International Arab Conference on Information Technology (ACIT) (pp. 1-6). IEEE.