{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/benchmarking-datasets-for-anomaly-based","title":"Benchmarking datasets for Anomaly-based Network Intrusion Detection: KDD CUP 99 alternatives","arxiv_id":"1811.05372","date":"2018-11-13","proceeding":null,"authors":["Abhishek Divekar","Meet Parekh","Vaibhav Savla","Rudra Mishra","Mahesh Shirole"],"abstract":"Machine Learning has been steadily gaining traction for its use in\nAnomaly-based Network Intrusion Detection Systems (A-NIDS). Research into this\ndomain is frequently performed using the KDD~CUP~99 dataset as a benchmark.\nSeveral studies question its usability while constructing a contemporary NIDS,\ndue to the skewed response distribution, non-stationarity, and failure to\nincorporate modern attacks. In this paper, we compare the performance for\nKDD-99 alternatives when trained using classification models commonly found in\nliterature: Neural Network, Support Vector Machine, Decision Tree, Random\nForest, Naive Bayes and K-Means. Applying the SMOTE oversampling technique and\nrandom undersampling, we create a balanced version of NSL-KDD and prove that\nskewed target classes in KDD-99 and NSL-KDD hamper the efficacy of classifiers\non minority classes (U2R and R2L), leading to possible security risks. We\nexplore UNSW-NB15, a modern substitute to KDD-99 with greater uniformity of\npattern distribution. We benchmark this dataset before and after SMOTE\noversampling to observe the effect on minority performance. Our results\nindicate that classifiers trained on UNSW-NB15 match or better the Weighted\nF1-Score of those trained on NSL-KDD and KDD-99 in the binary case, thus\nadvocating UNSW-NB15 as a modern substitute to these datasets.","url_abs":"http://arxiv.org/abs/1811.05372v1","url_pdf":"http://arxiv.org/pdf/1811.05372v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"benchmarking-datasets-for-anomaly-based","repo_url":"https://github.com/Saurabh2805/kdd_cup_99","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"benchmarking","task_name":"Benchmarking"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"},{"task_slug":"network-intrusion-detection","task_name":"Network Intrusion Detection"}],"methods":[{"method_slug":"smote","method_name":"SMOTE"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}