Research Article
Fusion of Heterogeneous Intrusion Detection Systems for Network Attack Detection
Table 6
Detection rate and false alarm rate of each classifier for test data.
| Attack type | Detection rate | False alarm rate | Anomaly-based | Signature-based | Anomaly-based | Signature-based | SVM | IBK | RandomForest | J48 | BayesNet | SVM | IBK | RandomForest | J48 | BayesNet |
| DOS | 95.4 | 99.5 | 99.7 | 99.6 | 93.7 | 0.7 | 0.3 | 0.2 | 0.1 | 0.3 | PROBE | 98.1 | 97.7 | 98.2 | 98.1 | 98.0 | 0.8 | 0.3 | 0.1 | 0.1 | 1.2 | U2R | 86.0 | 83.0 | 86.0 | 82.5 | 80.5 | 0.1 | 0.2 | 0.1 | 0.1 | 0.8 | R2L | 94.3 | 94.0 | 95.5 | 95.2 | 90.4 | 1.6 | 1.1 | 0.7 | 0.6 | 2.3 | Normal | 94.1 | 97.2 | 98.5 | 98.5 | 92.1 | 3.8 | 1.8 | 1.2 | 1.3 | 2.2 |
|
|