A PREPROCESSING PIPELINE FOR IMAGE CONSTRUCTION IN CNN-BASED MULTICLASS INTRUSION DETECTION

Dung Ha Thanh1,
1 Faculty of Information Technology, Saigon University (SGU)

Main Article Content

Abstract

Applying deep learning technology to build models to detect cyberattacks is a popular trend. In particular, visualising network data to create images familiar to CNN (Convolutional Neural Network) to have good classification as in computer vision is a very creative way. However, detecting many types of attacks using multilayer CNN classification models with imaged network datasets is still limited. In this paper, we propose a method to preprocess network data before converting it into images for input into multilayer CNN deep learning networks. This method was applied to process the NSL-KDD dataset with the separate KDDTest+ and showed competitive results. This result also shows that data preprocessing is still a necessary step when applying deep learning to building a network attack detection model.

Article Details

References

Patel, R. (2023, August 9). Protecting against sophisticated cyberattacks requires layered defenses. Forbes Technology Council.
Zhou, L., Pan, S., Wang, J., & Vasilakos, A. V. (2017). Machine learning on big data: Opportunities and challenges. Neurocomputing, 237, 350–361.
Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), 4396.
Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525–41550.
Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009). A detailed analysis of the KDD Cup 99 data set. In Proceedings of the IEEE Symposium on Computational Intelligence for Security and Defense Applications (pp. 1–6). IEEE.
Thaseen, I. S., & Kumar, C. A. (2017). Intrusion detection model using fusion of chi-square feature selection and multiclass SVM. Journal of King Saud University – Computer and Information Sciences, 29(4), 462–472.
Tama, B. A., Comuzzi, M., & Rhee, K.-H. (2019). TSE-IDS: A two-stage classifier ensemble for intelligent anomaly-based intrusion detection system. IEEE Access, 7, 94497–94507.
Aldweesh, A., Derhab, A., & Emam, A. Z. (2019). Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues. Knowledge-Based Systems, 189, 105124.
Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2019). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419.
Altwaijry, N., Alqahtani, A., & Al-Turaiki, I. (2019). A deep learning approach for anomaly-based network intrusion detection. In Y. Tian, T. Ma, & M. K. Khan (Eds.), Proceedings of the First International Conference on Big Data and Security. Springer.
Masum, M., Shahriar, H., & Haddad, H. M. (2021). A transfer learning with deep neural network approach for network intrusion detection. International Journal of Intelligent Computing Research, 12(1), 1087–1095.
He, H., Bai, Y., Garcia, E. A., & Li, S. (2008). ADASYN: Adaptive synthetic sampling approach for imbalanced learning. In Proceedings of the IEEE International Joint Conference on Neural Networks (pp. 1322–1328). IEEE.
Potdar, K. (2017). A comparative study of categorical variable encoding techniques for neural network classifiers. International Journal of Computer Applications, 175(4).
Al-Turaiki, I., & Altwaijry, N. (2021). A convolutional neural network for improved anomaly-based network intrusion detection. Cybersecurity, 4(3).
Yin, C., Zhu, Y., Fei, J., & He, X. (2017). A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access, 5, 21954–21961.
Al-Qatf, M., Lasheng, Y., Al-Habib, M., & Al-Sabahi, K. (2018). Deep learning approach combining sparse autoencoder with SVM for network intrusion detection. IEEE Access, 6, 52843–52856.
NSL-KDD Dataset. (n.d.). NSL-KDD intrusion detection dataset. https://www.unb.ca/cic/datasets/nsl.html
Sherin, V. J. I. J., & Radhika, N. (2022). Stacked ensemble IDS using NSL-KDD dataset. Journal of Pharmaceutical Negative Results, 13(3).
Dhanabal, L., & Shantharajah, S. (2015). A study on NSL-KDD dataset for intrusion detection system based on classification algorithms. International Journal of Advanced Research in Computer and Communication Engineering, 4(6), 446–452.
Dung, H. T., & Nguyen, H. S. (2023). A data preprocessing method prior to imaging for training deep learning-based network intrusion detection models. In Proceedings of the 26th National Conference on Electronics, Communications and Information Technology (REV-ECIT 2023) (pp. 311–316). Information and Communications Publishing House.
Jang, J., An, Y., Kim, D., & Choi, D. (2023). Feature importance-based backdoor attack in NSL-KDD. Electronics, 12(24), 4953. https://doi.org/10.3390/electronics12244953
Iftikhar, N., Rehman, M. U., Shah, M. A., Alenazi, M. J. F., & Ali, J. (2025). Intrusion detection in NSL-KDD dataset using hybrid self-organizing map model. Computer Modeling in Engineering & Sciences, 143(1), 639–671.
Wu, Y., & Hu, X. (2022). An intrusion detection method based on fully connected recurrent neural network. Scientific Programming, 2022, 1–11. https://doi.org/10.1155/2022/7777211
Wisanwanichthan, T., & Thammawichai, M. (2025). A lightweight intrusion detection system for IoT and UAV using deep neural networks with knowledge distillation. Computers, 14(7). https://doi.org/10.3390/computers14070291