Perbandingan Algoritma Random Forest, K-Nearest Neighbor, dan Support Vector Machine Untuk Deteksi Anomali Trafik Jaringan Menggunakan Dataset CICIDS2017

Authors

  • Siti Zamili Universitas Negeri Medan
  • Dedy Kiswanto Universitas Negeri Medan
  • Khodotun Hadawiyah Margolang Universitas Negeri Medan

Keywords:

K-Nearest Neighbor, Support Vector Machine, Random Forest, Deteksi Anomali, Intrusion Detection System

Abstract

The increasingly complex development of cyber threats has driven the need for network protection systems capable of detecting intrusions intelligently and automatically. Machine learning-based approaches have been widely adopted as intrusion detection solutions due to their ability to recognize attack patterns without relying on manually defined rules. This study examines the effectiveness of four machine learning algorithms, namely Random Forest, Decision Tree, Stacked LSTM, and AdaBoost, in network traffic classification tasks using the CICIDS2017 dataset as the evaluation benchmark. Before model training, the data was processed through normalization and relevant feature selection stages to ensure optimal data representation. Model performance was measured using four main evaluation metrics, namely accuracy, precision, recall, and F1-score, to obtain a comprehensive assessment of the  classification capability of each algorithm. From the test results, Decision Tree stood out with a precision value reaching 99.87%, recall of 99.59%, and F1-score of 99.32%, indicating excellent per-class classification capability with a very low error rate. On the other hand, Random Forest recorded the highest overall accuracy value of 99.90%, accompanied by a precision of 97.78%, recall of 97.08%, and F1-score of 97.41%, reflecting the model's reliability in consistently maintaining performance across all classes. Both the Stacked LSTM and AdaBoost-based models showed lower performance compared to tree-based approaches in the same testing scenario. Overall, the results of this study confirm that decision tree-based algorithms offer a combination of high accuracy and superior classification stability, making them the right choice for implementing machine learning-based network intrusion detection systems.

Downloads

Download data is not yet available.

References

Maulana and Alamsyah, “48231-124397-1-SM 1,” Indonesian Journal of Mathematics and Natural Sciences, vol. 46, no. 2, pp. 83–92, Oct. 2023, doi: http://journal.unnes.ac.id/nju/index.php/JM.

M. Ramzan et al., “Distributed Denial of Service Attack Detection in Network Traffic Using Deep Learning Algorithm,” Sensors (Basel), vol. 23, no. 20, Oct. 2023, doi: 10.3390/s23208642.

U. Ahmed et al., “Signature-based intrusion detection using machine learning and deep learning approaches empowered with fuzzy clustering,” Sci. Rep., vol. 15, no. 1, Dec. 2025, doi: 10.1038/s41598-025-85866-7.

M. Ismail Mohmand et al., “A Machine Learning based Classification and Prediction Technique for DDoS Attacks,” vol. 4, pp. 1–13, 2022, doi: 10.1109/ACCESS.2017.DOI.

Y. Yang, Y. Zhang, L. Yang, and Y. Wang, “Wideband Direction-of-Arrival Estimation Based on Hierarchical Sparse Bayesian Learning for Signals with the Same or Different Frequency Bands,” Electronics (Switzerland), vol. 12, no. 5, Mar. 2023, doi: 10.3390/electronics12051123.

A. Momand, S. U. Jan, and N. Ramzan, “A Systematic and Comprehensive Survey of Recent Advances in Intrusion Detection Systems Using Machine Learning: Deep Learning, Datasets, and Attack Taxonomy,” 2023, Hindawi Limited. doi: 10.1155/2023/6048087.

M. K. Ngueajio, G. Washington, D. B. Rawat, and Y. Ngueabou, “Intrusion Detection Systems Using Support Vector Machines on the KDDCUP’99 and NSL-KDD Datasets. A Comprehensive Survey,” 2022. doi: arXivpreprint,arXiv:2209.05579.

A. Rosay, E. Cheval, F. Carlier, and P. Leroux, “Network Intrusion Detection: A Comprehensive Analysis of CIC-IDS2017,” in International Conference on Information Systems Security and Privacy, Science and Technology Publications, Lda, 2022, pp. 25–36. doi: 10.5220/0010774000003120.

N. F. Rozam, T. N. Sari, M. R. A. Yudianto, and D. F. Rahman, “Machine Learning-Based Network Traffic Anomaly Detection Using the CIC-IDS2017 Dataset,” UPGRADE : Jurnal Pendidikan Teknologi Informasi, vol. 3, no. 2, Apr. 2026, doi: 10.30812/upgrade.v3i2.6174.

M. Abushwereb, M. Al-Kasassbeh, M. Almseidin, and M. Mustafa, “An accurate IoT Intrusion Detection Framework using Apache Spark,” 2022. doi: arXivpreprintarXiv:2203.04347.

M. Rodríguez, Á. Alesanco, L. Mehavilla, and J. García, “Evaluation of Machine Learning Techniques for Traffic Flow-Based Intrusion Detection,” Sensors, vol. 22, no. 23, Dec. 2022, doi: 10.3390/s22239326.

D. Kiswanto, F. Ramadhani, N. M. Surbakti, N. A. Nasution, F. Matematika, and I. P. Alam, “Pengembangan dan Implementasi Sistem Deteksi Serangan DDoS Berbasis Algoritma Random Forest,” Bulletin of Information Technology (BIT), vol. 6, no. 3, pp. 247–256, 2025, doi: 10.47065/bit.v5i2.2203.

S. S. Tripathy and B. Behera, “A Review of Various Datasets for Machine Learning Algorithm-Based Intrusion Detection System: Advances and Challenges,” May 2024. doi: www.ijisae.org.

A. W. Ningrum, M. P. Aji, E. S. Wijaya, and E. A. Pambudi, “Deteksi dan Klasifikasi Ancaman pada Log Serangan Siber Menggunakan Algoritma K-Nearest Neighbor (KNN) dan Random Forest (RF),” Jurnal Pendidikan dan Teknologi Indonesia, vol. 5, no. 12, pp. 3610–3619, Jan. 2026, doi: 10.52436/1.jpti.1197.

A. Singh, J. Amutha, J. Nagar, S. Sharma, and C. C. Lee, “LT-FS-ID: Log-Transformed Feature Learning and Feature-Scaling-Based Machine Learning Algorithms to Predict the k-Barriers for Intrusion Detection Using Wireless Sensor Network,” Sensors, vol. 22, no. 3, Feb. 2022, doi: 10.3390/s22031070.

J. M. H. Pinheiro et al., “The Impact of Feature Scaling in Machine Learning: Effects on Regression and Classification Tasks,” IEEE Access, vol. 11, pp. 199903–199931, 2025, doi: 10.1109/ACCESS.2025.3635541.

S. Sekhar Tripathy and B. Behera, “ Hyperparameter Tuning-based Optimized Analysis of Machine Learning Algoritma For Network Intrusion Detection,” International Journal of Network Security & Its Applications, vol. 17, no. 6, pp. 01–26, Nov. 2025, doi: 10.5121/ijnsa.2025.17601.

T. H. Chua and I. Salam, “Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection Using Progressive Dataset,” Symmetry (Basel)., vol. 15, no. 6, Jun. 2023, doi: 10.3390/sym15061251.

D. P. Sari, Z. Halim, I. Irlon, B. Waseso, and S. Saromah, “Implementasi Machine Learning untuk Deteksi Intrusi pada Jaringan Komputer,” Jurnal Minfo Polgan, vol. 13, no. 2, pp. 1389–1394, Sep. 2024, doi: 10.33395/jmp.v13i2.14074.

M. T. Abdelaziz et al., “Enhancing Network Threat Detection with Random Forest-Based NIDS and Permutation Feature Importance,” Journal of Network and Systems Management, vol. 33, no. 1, Mar. 2025, doi: 10.1007/s10922-024-09874-0.

A. Alqahtani and H. Alshaher, “Anomaly-Based Intrusion Detection Systems Using Machine Learning,” Journal of Cybersecurity and Information Management, vol. 14, no. 1, pp. 20–33, 2024, doi: 10.54216/JCIM.140102.

Md. A. Talukder et al., “Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction,” Jan. 2024, [Online]. Available: http://arxiv.org/abs/2401.12262

A. Sapaatullah and M. Darip, “Implementasi One-Class Support Vector Machine untuk Deteksi Serangan Jaringan Kampus,” Bulletin of Information Technology (BIT), vol. 7, no. 1, pp. 40–49, 2026, doi: 10.47065/bit.v5i2.2602.

A. T. Zy, A. T. Sasongko, and A. Z. Kamalia, “Penerapan Naïve Bayes Classifier, Support Vector Machine, dan Decision Tree untuk Meningkatkan Deteksi Ancaman Keamanan Jaringan,” Media Online), vol. 4, no. 1, pp. 610–617, 2023, doi: 10.30865/klik.v4i1.1134.

K. A. Nugroho, T. Hariguna, and A. S. Barkah, “Optimizing Early Network Intrusion Detection: A Comparison of LSTM and LinearSVC with SMOTE on Imbalanced Data,” Jurnal Teknik Informatika (Jutif), vol. 6, no. 6, pp. 5349–5370, Dec. 2025, doi: 10.52436/1.jutif.2025.6.6.4672.

H. Haeruddin, E. Erick, and H. W. Aripradono, “Perbandingan Support Vector Machine, Random Forest Classifier, dan K-Nearest Neighbour dalam Pendeteksian Anomali pada Jaringan DDos,” JTIM : Jurnal Teknologi Informasi dan Multimedia, vol. 7, no. 1, pp. 23–33, Jan. 2025, doi: 10.35746/jtim.v7i1.628.

S. Rabbani and D. Diana, “Prediksi Kategori Serangan Siber dengan Algoritma Klasifikasi Random Forest Menggunakan Rapidminer,” SMATIKA JURNAL, vol. 13, no. 02, pp. 284–293, Dec. 2023, doi: 10.32664/smatika.v13i02.934.

E. Altulaihan, M. A. Almaiah, and A. Aljughaiman, “Anomaly Detection IDS for Detecting DoS Attacks in IoT Networks Based on Machine Learning Algorithms,” Sensors, vol. 24, no. 2, Jan. 2024, doi: 10.3390/s24020713.

Downloads

Published

2026-10-07