Skip to content
Open access

Z-Shield: A Lightweight Hybrid Browser-Based Intrusion Detection Framework Using Hybrid Machine Learning

2026 · International journal of research and innovation in applied science · Vol 11, pp. 295-304 · 0 citations

TL;DR

Z-Shield is introduced, a real-time detection framework built as a Google Chrome extension and organised around a three-tier architecture that resolves in under 100 milliseconds end-to-end, which keeps it usable for everyday browsing rather than just the lab.

Abstract

Client-side attacks such as cross-site scripting, SQL injection, and command-and-control traffic increasingly slip past server-centric defences because the browser itself is where the damage happens. This paper introduces Z-Shield, a real-time detection framework built as a Google Chrome extension and organised around a three-tier architecture. At its core is a hybrid engine: a supervised Random Forest handles known attack categories, while an unsupervised Isolation Forest watches for the zero-day cases no labelled dataset could have anticipated. We evaluate the system on the BCCC-CSE-CIC-IDS2018 dataset using five behavioural flow metrics: Flow Duration, Total Forward Packets, Total Backward Packets, Mean Packet Length, and Flow Inter-Arrival Time Mean. The supervised layer reaches 99.13% accuracy, 99.90% precision, 99.27% recall, and a 99.58% F1-score, and the unsupervised layer peaks at 97.09% isolation accuracy, ahead of the 93% benchmark reported by prior work. Importantly, the full pipeline resolves in under 100 milliseconds end-to-end, which keeps it usable for everyday browsing rather than just the lab.

Read PDF

Similar papers

Open access Sep 2026

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic cap...

Zeyneb Berkat, Amina Fatima Zahra Yahiaoui, Mahfoud Aliouat et al. · 0 citations
Open access Aug 2026

ZeroProbe: An Intelligent Web-Based Vulnerability Scanner Integrating Automated Detection and AI-Based Analysis

The findings confirm that an accessible, accurate, and AI-augmented vulnerability scanner can be constructed for educational and entry-level use within a deliberately bounded scope, lowering the expertise barrier for web application security assessment.

Dah Berrou, Zaenal Alamsyah, Nugraha Nugraha · 0 citations
Open access Aug 2026

Enhancing SQL Injection Detection: A Machine Learning Approach Using Network Flow Data

A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.

P. Vinoth, K. Sudar, S. Muthukumar · 0 citations
#generative ai Open access Sep 2026

Hive-AI: a defended multi-service honeypot framework for generative AI APIs

HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.

Sebastián Vargas Yáñez, Sergio Tobón · 1 citation
Open access Aug 2026

Browser-based phishing detection system using modern web technologies

A hybrid browser-resident phishing detection framework that combines three complementary detection mechanisms: a locally executed Random Forest model using URL lexical features, lightweight real-time DOM structure analysis, and VirusTotal’s multi-engine reputation service is proposed.

Muhammad Arshad, Beena Sherin Kuriakose, C. W. Onn et al. · 0 citations
Open access Sep 2026

A Real-Time eBPF-Based Intrusion Detection Framework for Adaptive and Scalable Linux Kernel Security

The Linux kernel represents a critical attack surface due to its privileged execution level, making it a frequent target for attacks such as privilege escalation and advanced persistent threats (APTs). Traditional intrusion detection systems (IDS)typically operate in user space and rely on static or signature based te...

Maryam Alaa Zaki, Nuha Omran Abokhdair · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.