🤖 AI Summary
The selection of network traffic feature extraction tools for AI-driven intrusion detection systems (AI-IDS) lacks systematic, comparative evaluation. Method: This study establishes a unified experimental framework to conduct the first horizontal comparison of statistical (CICFlowMeter, tshark), sequential (LSTM-Autoencoder), and textual (TF-IDF) feature extraction methods, integrated with XGBoost, CNN, and LSTM classifiers. Performance is evaluated across detection accuracy, computational overhead, and feature redundancy. Contribution/Results: We propose evidence-based feature tool selection guidelines for AI-IDS: CICFlowMeter achieves optimal trade-off between accuracy (98.7%) and efficiency; deep-learning–based methods significantly improve APT detection F1-score (+12.3%) but incur 4.8× higher inference latency. Our findings provide empirical support and practical guidance for designing high-discriminative, scalable network traffic representations in AI-IDS.
📝 Abstract
The comparison analysis of the most popular tools to extract features from network traffic is conducted in this paper. Feature extraction plays a crucial role in Intrusion Detection Systems (IDS) because it helps to transform huge raw network data into meaningful and manageable features for analysis and detection of malicious activities. The good choice of feature extraction tool is an essential step in construction of Artificial Intelligence-based Intrusion Detection Systems (AI-IDS), which can help to enhance the efficiency, accuracy, and scalability of such systems.