Klasifikasi Multi-Kelas Serangan Jaringan Menggunakan Algoritma Random Forest pada Dataset NSL-KDD

Authors

  • Ajeng Hidayati Universitas Pertahanan Republik Indonesia

DOI:

https://doi.org/10.59585/jimad.v4i1.1680

Keywords:

Machine Learning, Klasifikasi Serangan Jaringan, Random Forest, Intrusion Detection System, NSL-KDD

Abstract

Serangan siber pada jaringan komputer terus meningkat baik dari sisi volume maupun kompleksitas, sehingga dibutuhkan sistem deteksi intrusi yang mampu mengklasifikasikan jenis serangan secara akurat. Penelitian ini bertujuan membandingkan kinerja algoritma Random Forest, Decision Tree, dan Naive Bayes dalam mengklasifikasikan lalu lintas jaringan ke dalam lima kategori, yaitu Normal, Denial of Service (DoS), Probe, Remote to Local (R2L), dan User to Root (U2R). Metode yang digunakan adalah eksperimen klasifikasi multi-kelas pada dataset benchmark NSL-KDD, meliputi tahap praproses data, pelatihan model, dan evaluasi menggunakan metrik akurasi, presisi, recall, dan F1-score pada data uji independen (KDDTest+). Hasil penelitian menunjukkan Decision Tree memperoleh akurasi tertinggi (76,15%), sedikit di atas Random Forest (75,00%), sementara Naive Bayes jauh tertinggal (28,71%). Kedua model berbasis pohon keputusan mampu mendeteksi kategori Normal dan DoS dengan baik, namun mengalami kesulitan signifikan mendeteksi serangan R2L dan U2R akibat ketidakseimbangan kelas pada data latih serta adanya pola serangan baru pada data uji. Analisis feature importance menunjukkan src_bytes, same_srv_rate, dan flag sebagai fitur paling berpengaruh. Temuan ini menegaskan perlunya strategi penyeimbangan data untuk meningkatkan deteksi serangan minoritas pada sistem keamanan jaringan berbasis machine learning

Downloads

Download data is not yet available.

References

Azam, Z., Islam, M. M., & Huda, M. N. (2023). Comparative analysis of intrusion detection systems and machine learning-based model analysis through decision tree. IEEE Access, 11, 80348–80391. https://doi.org/10.1109/ACCESS.2023.3296444

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324

Chawla, N. V., Bowyer, K. W., Hall, L. O., & Kegelmeyer, W. P. (2002). SMOTE: Synthetic minority over-sampling technique. Journal of Artificial Intelligence Research, 16, 321–357. https://doi.org/10.1613/jair.953

Chen, D., Song, Q., Zhang, Y., Li, L., & Yang, Z. (2023). Identification of network traffic intrusion using decision tree. Journal of Sensors, 2023, Article 5997304. https://doi.org/10.1155/2023/5997304

Fernandes, G., Rodrigues, J. J. P. C., & Carvalho, L. F. (2019). A comprehensive survey on network anomaly detection. Telecommunication Systems, 70(3), 447–489. https://doi.org/10.1007/s11235-018-0475-8

Iftikhar, N., Rehman, M. U., Shah, M. A., Alenazi, M. J. F., & Ali, J. (2025). Intrusion detection in NSL-KDD dataset using hybrid self-organizing map model. Computer Modeling in Engineering & Sciences, 143(1), 639–671. https://doi.org/10.32604/cmes.2025.062788

Koc, L., Mazzuchi, T. A., & Sarkani, S. (2012). A network intrusion detection system based on a Hidden Naïve Bayes multiclass classifier. Expert Systems with Applications, 39(18), 13492–13500.

Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), 4396. https://doi.org/10.3390/app9204396

Negandhi, P., Trivedi, Y., & Mangrulkar, R. (2019). Intrusion detection system using random forest on the NSL-KDD dataset. In N. Shetty, L. M. Patnaik, H. C. Nagaraj, P. N. Hamsavath, & N. Nalini (Eds.), Emerging research in computing, information, communication and applications (pp. 519–529). Springer. https://doi.org/10.1007/978-981-13-6001-5_43

Panda, M., & Patra, M. R. (2007). Network intrusion detection using naive bayes. International Journal of Computer Science and Network Security, 7(12), 258–263.

Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., & Duchesnay, E. (2011). Scikit-learn: Machine learning in Python. Journal of Machine Learning Research, 12, 2825–2830.

Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA). https://doi.org/10.1109/CISDA.2009.5356528

Thakkar, A., & Lohiya, R. (2021). Attack classification using feature selection techniques: a comparative study. Journal of Ambient Intelligence and Humanized Computing, 12(1), 1249–1266. https://doi.org/10.1007/s12652-020-02167-9

Wu, T., Fan, H., Zhu, H., You, C., Zhou, H., & Huang, X. (2022). Intrusion detection system combined enhanced random forest with SMOTE algorithm. EURASIP Journal on Advances in Signal Processing, 2022, Article 39. https://doi.org/10.1186/s13634-022-00871-6

Zou, L., Luo, X., Zhang, Y., Yang, X., & Wang, X. (2023). HC-DTTSVM: A network intrusion detection method based on decision tree twin support vector machine and hierarchical clustering. IEEE Access, 11, 21404–21416. https://doi.org/10.1109/ACCESS.2023.3251354

Downloads

Published

2026-09-11

How to Cite

Hidayati, A. (2026). Klasifikasi Multi-Kelas Serangan Jaringan Menggunakan Algoritma Random Forest pada Dataset NSL-KDD. JIMAD : Jurnal Ilmiah Multidisiplin, 4(1), 48–55. https://doi.org/10.59585/jimad.v4i1.1680