A Crow Search-Optimized K-Nearest Neighbors Framework for Intrusion Detection in Government Security Networks
DOI:
https://doi.org/10.59675/E421Keywords:
Intrusion Detection System; Crow Search Algorithm; K-Nearest Neighbors; Feature Selection; NSL-KDD; Network Security; Meta-heuristic OptimizationAbstract
The growing dependence of e-government services on interconnected infrastructure has made government security networks an increasingly attractive target for sophisticated cyber-attacks. Machine-learning-based intrusion detection systems (IDS) provide an adaptive line of defence, but their accuracy and computational cost are highly sensitive to the number and quality of input features. This paper proposes a wrapper-based feature-selection framework that couples the Crow Search Algorithm (CSA) — a swarm-intelligence meta-heuristic inspired by the food-hoarding behaviour of crows — with a K-Nearest Neighbors (KNN) classifier for multi-class network intrusion detection. A binary variant of CSA searches the feature space of the benchmark NSL-KDD dataset using the cross-validated accuracy of a KNN classifier as its fitness function, converging on a subset of 18 of the original 41 traffic features (a 56% reduction). The resulting CSA-KNN model is evaluated under two protocols: (i) an in-sample 80/20 split of the KDDTrain+ partition, and (ii) the official, more challenging KDDTest+ partition, which contains attack types absent from training and is therefore a realistic proxy for zero-day threats. CSA-KNN attains 99.43% accuracy under the in-sample protocol and 76.00% accuracy (81.79% weighted precision, 73.06% weighted F1-score) on the unseen KDDTest+ set, improving on a plain KNN that uses all 41 features on every metric while requiring 56% fewer input dimensions, and performing competitively against Logistic Regression, Decision Tree and Random Forest baselines evaluated under an identical protocol. The results confirm that CSA-based feature selection can reduce the dimensionality and computational footprint of KNN-based IDS without sacrificing detection performance, while also illustrating the well-documented optimism gap between in-sample and true generalization performance on NSL-KDD — an issue often overlooked in the intrusion-detection literature. The lightweight computational profile of the proposed approach makes it a practical candidate for near-real-time monitoring of government security networks.
References
1. Wylde V, et al. Cybersecurity, data privacy and blockchain: a review. SN Comput Sci. 2022;3(2):1-12. doi:10.1007/s42979-022-01020-4.
2. Laghari AA, Wu K, Laghari RA, Ali M, Khan AA. A review and state of art of Internet of Things (IoT). Arch Comput Methods Eng. 2022;29(3):1395-413. doi:10.1007/s11831-021-09622-6.
3. Cui Y, et al. Towards DDoS detection mechanisms in software-defined networking. J Netw Comput Appl. 2021; 190:103156. doi:10.1016/j.jnca.2021.103156.
4. Lee E, Seo YD, Oh SR, Kim YG. A survey on standards for interoperability and security in the Internet of Things. IEEE Commun Surv Tutor. 2021;23(2):1020-47. doi:10.1109/COMST.2021.3067354.
5. Thakkar A, Lohiya R. A review on machine learning and deep learning perspectives of IDS for IoT: recent updates, security issues, and challenges. Arch Comput Methods Eng. 2021;28(4). doi:10.1007/s11831-020-09496-0.
6. Li Y, Liu Q. A comprehensive review study of cyber-attacks and cyber security: emerging trends and recent developments. Energy Rep. 2021; 7:8176-86. doi:10.1016/j.egyr.2021.08.126.
7. Ma X, et al. A comprehensive survey on graph anomaly detection with deep learning. IEEE Trans Knowl Data Eng. 2021. doi:10.1109/TKDE.2021.3118815.
8. Nassif AB, Talib MA, Nasir Q, Dakalbab FM. Machine learning for anomaly detection: a systematic review. IEEE Access. 2021; 9:78658-700. doi:10.1109/ACCESS.2021.3083060.
9. Altaha M, Lee JM, Aslam M, Hong S. An autoencoder-based network intrusion detection system for the SCADA system. J Commun. 2021;16(6):210-6. doi:10.12720/jcm.16.6.210-216.
10. Moualla S, Khorzom K, Jafar A. Improving the performance of machine learning-based network intrusion detection systems on the UNSW-NB15 dataset. Comput Intell Neurosci. 2021;2021:5557577. doi:10.1155/2021/5557577.
11. Kumar R, Kumar P, Tripathi R, Gupta GP, Garg S, Hassan MM. A distributed intrusion detection system to detect DDoS attacks in blockchain-enabled IoT network. J Parallel Distrib Comput. 2022;164:55-68. doi:10.1016/j.jpdc.2022.01.030.
12. Chaudhary P, Gupta B, Singh AK. Implementing attack detection system using filter-based feature selection methods for fog-enabled IoT networks. Telecommun Syst. 2022;81(1):23-39. doi:10.1007/s11235-022-00927-w.
13. Abdullayeva FJ. Distributed denial of service attack detection in e-government cloud via data clustering. Array. 2022;15:100229. doi:10.1016/j.array.2022.100229.
14. Xing N, Zhao S, Wang Y, Ning K, Liu X. A dynamic intrusion detection system capable of detecting unknown attacks. Int J Adv Comput Sci Appl. 2023;14(7). doi:10.14569/IJACSA.2023.0140743.
15. Mittal M, Kumar K, Behal S. DL-2P-DDoSADF: deep learning-based two-phase DDoS attack detection framework. J Inf Secur Appl. 2023;78:103609. doi:10.1016/j.jisa.2023.103609.
16. Mohamed TS, Khalifah SM. Intrusion detection systems: a revisit of performance evaluation parameters. Acad Int J Eng Sci. 2024;2(1):15-21. doi:10.59675/E212.
17. Mohamed TS, Aydin S, Alkhayyat A, Malik RQ. Kalman and Cauchy clustering for anomaly detection based authentication of IoMTs using extreme learning machine. IET Commun. 2025;19(1):e12467. doi:10.1049/cmu2.12467.
18. Gupta C, Kumar A, Jain NK. An enhanced hybrid intrusion detection based on crow search analysis optimizations and artificial neural network. Wirel Pers Commun. 2024;134(1):43-68. doi:10.1007/s11277-024-10880-3.
19. Gupta C, Kumar A, Jain NK. Intelligent intrusion detection system based on crowd search optimization for attack classification in network security. EURASIP J Inf Secur. 2025;2025(1):22. doi:10.1186/s13635-025-00205-7.
20. Askarzadeh A. A novel metaheuristic method for solving constrained engineering optimization problems: crow search algorithm. Comput Struct. 2016;169:1-12. doi:10.1016/j.compstruc.2016.03.001.
21. Chawla NV, Bowyer KW, Hall LO, Kegelmeyer WP. SMOTE: synthetic minority over-sampling technique. J Artif Intell Res. 2002;16:321-57. doi:10.1613/jair.953.
22. Demšar J. Statistical comparisons of classifiers over multiple data sets. J Mach Learn Res. 2006;7:1-30.
23. Sokolova M, Lapalme G. A systematic analysis of performance measures for classification tasks. Inf Process Manag. 2009;45(4):427-37. doi:10.1016/j.ipm.2009.03.002.
24. Brodersen KH, Ong CS, Stephan KE, Buhmann JM. The balanced accuracy and its posterior distribution. In: Proceedings of the 20th International Conference on Pattern Recognition (ICPR). 2010:3121-4. doi:10.1109/ICPR.2010.764.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Academic International Journal of Engineering Sciences

This work is licensed under a Creative Commons Attribution 4.0 International License.


