Authors: Halimah Muhammad Tukur, Jamilu Awwalu, Salim Ahmad, Ayuba John
Abstract: The evolving sophistication of cyber threats, particularly denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks, poses significant challenges to the modern cybersecurity systems, availability, and reliability of digital infrastructures. These attacks often overwhelm network resources, leading to service disruptions and potential data breaches. Traditional intrusion detection systems (IDS) have been developed to mitigate such threats; however, they often struggle with scalability, detection accuracy, and interpretability, especially when processing large-scale network traffic. To address these limitations, this study proposes a stacked ensemble intrusion detection model integrating Decision Tree (DT), Random Forest (RF), and Artificial Neural Network (ANN) classifiers as base learners, with Logistic Regression (LR) serving as the meta-learner. The framework aims to enhance detection accuracy, interpretability, and robustness against DoS and DDoS attacks. Using the CIC-IDS2017 dataset, Mutual Information (MI) was employed for optimal feature selection, ensuring the most relevant attributes were retained for training. SHAP (Shapley Additive exPlanations) was applied to interpret the contribution of each selected feature to the model’s decision-making process. Experimental results demonstrate that the proposed ensemble achieves superior performance compared to individual classifiers and baseline models, with 98.83% accuracy, a marginal precision trade-off (96.37% vs. 96.50% baseline), 99.19% recall, 97.76% F1-score, and an AUC of 99.95%. Compared with the baseline [1], recall improved by 3.39% and F1-score by 1.57%. SHAP analysis identified flow-based and packet-based features as key contributors in distinguishing normal and malicious traffic. Overall, combining multiple learning algorithms within a stacked ensemble, along with MI feature selection and SHAP explainability, provides a robust, transparent, and effective solution for real-time intrusion detection.
International Journal of Science, Engineering and Technology