2026· International journal of research and innovation in applied science· Vol 11, pp. 295-304· 0 citations
TL;DR
Z-Shield is introduced, a real-time detection framework built as a Google Chrome extension and organised around a three-tier architecture that resolves in under 100 milliseconds end-to-end, which keeps it usable for everyday browsing rather than just the lab.
Abstract
Client-side attacks such as cross-site scripting, SQL injection, and command-and-control traffic increasingly slip past server-centric defences because the browser itself is where the damage happens. This paper introduces Z-Shield, a real-time detection framework built as a Google Chrome extension and organised around a three-tier architecture. At its core is a hybrid engine: a supervised Random Forest handles known attack categories, while an unsupervised Isolation Forest watches for the zero-day cases no labelled dataset could have anticipated. We evaluate the system on the BCCC-CSE-CIC-IDS2018 dataset using five behavioural flow metrics: Flow Duration, Total Forward Packets, Total Backward Packets, Mean Packet Length, and Flow Inter-Arrival Time Mean. The supervised layer reaches 99.13% accuracy, 99.90% precision, 99.27% recall, and a 99.58% F1-score, and the unsupervised layer peaks at 97.09% isolation accuracy, ahead of the 93% benchmark reported by prior work. Importantly, the full pipeline resolves in under 100 milliseconds end-to-end, which keeps it usable for everyday browsing rather than just the lab.
Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic cap...
The findings confirm that an accessible, accurate, and AI-augmented vulnerability scanner can be constructed for educational and entry-level use within a deliberately bounded scope, lowering the expertise barrier for web application security assessment.
A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.
P. Vinoth, K. Sudar, S. Muthukumar· Journal of Computer Science· 0 citations
HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.
Sebastián Vargas Yáñez, Sergio Tobón· International Journal of Inf...· 1 citation
A hybrid browser-resident phishing detection framework that combines three complementary detection mechanisms: a locally executed Random Forest model using URL lexical features, lightweight real-time DOM structure analysis, and VirusTotal’s multi-engine reputation service is proposed.
Muhammad Arshad, Beena Sherin Kuriakose, C. W. Onn et al.· Frontiers of Computer Scienc...· 0 citations
The Linux kernel represents a critical attack surface due to its privileged execution level, making it a frequent target for attacks such as privilege escalation and advanced persistent
threats (APTs). Traditional intrusion detection systems (IDS)typically operate in user space and rely on static or signature based te...