Comparative Analysis of Random Forests and Gradient Boosting for SNMP-MIB Intrusion Detection Using Feature Selection Techniques
Abstract
Despite advancements in machine learning techniques for network intrusion detection, significant gaps still exist in the comparative analysis of tree-based ensemble models for network intrusion detection using lightweight Simple Management Network Protocol Management Information Base (SNMP-MIB) data and in the integration of multi-stage feature selection with the same data. This research, therefore, provides an empirical comparative analysis of two popular tree-based ensemble models- Random Forest (RF) and Gradient Boosting (GB), for binary intrusion detection using SNMP-MIB data. It also investigates the impact of a multi-stage feature selection pipeline on model performance, computational efficiency, and practical deployability. The SNMP-MIB dataset used comprises 4,998 instances and 34 features. Data preprocessing involved normalisation and balancing, using the Synthetic Minority Oversampling Technique (SMOTE). The multi-stage feature selection involves Mutual Information (MI), Recursive Feature Elimination (RFE) and Spearman Correlation Filtering. Both RF and GB were trained and evaluated using standard metrics. From the results of the study, both models achieve exceptional performance exceeding 99.9% accuracy across all three feature selection methods. GB had a higher accuracy of 99.97%, marginally outperforming RF (99.95%). While both models recorded zero false negatives, RF exhibited greater stability to feature set variation (0.04%) compared to GB (0.07%). The dimensionality was also reduced from 34 to 9 features (74.5%), with no decline in accuracy, implying that gradual dimension reduction by eliminating redundant features does not reduce the effectiveness of the model. These findings validate SNMP-MIB with optimised feature selection as an efficient and lightweight data source for real-time intrusion detection in a resource-constrained environment. The selected feature sets significantly reduced computational complexity while improving real-time detection capacity, and the multi-stage feature selection pipeline offers a scalable technique to dimensionality reduction in network security. This study, therefore, establishes a guide for practitioners' decisions in real-time intrusion detection deployments regarding the trade-offs between peak performance (GB) and operational stability (RF) for a specific model.