Jul 2026· 2026 5th International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE)· pp. 1-6· 0 citations· 23 references
Abstract
The increasing complexity and frequency of cyberattacks have heightened the need for intrusion detection systems capable of recognizing threats that extend beyond predefined signatures. Traditional signature-based IDS solutions are often insufficient for detecting newly emerging or evolving attack patterns. This work presents a supervised machine learning approach for network intrusion detection, employing the NSL-KDD dataset to classify network traffic as either normal or malicious. The study investigates the performance of several classifiers, comprising Decision Trees, Random Forest, Logistic Regression, k-Nearest Neighbors (k-NN), and Support Vector Machines (SVM). The proposed framework incorporates key preprocessing procedures such as feature normalization, dimensionality reduction, and attribute filtering to enhance model robustness. The proposed models are evaluated using accuracy, precision, recall, and F1-score, with special consideration given to minimizing false positives to enhance real-time detection effectiveness. Experimental findings demonstrate that supervised learning models exhibit improved detection capability and better adaptability to unfamiliar attack behaviors. The results highlight the potential of machine learning techniques as scalable and effective components of modern network security architectures.
Intrusion Detection Systems (IDSs) play a vital role in safeguarding modern network infrastructures against increasingly sophisticated cyber threats. However, the high dimensionality of network traffic data and the presence of imbalanced attack classes often limit the effectiveness of conventional Machine Learning (ML) approaches. This study proposes a feature-driven Intrusion Detection (ID) framework that combines XGBoost-based feature selection with multiple ML classifiers to improve attack detection performance while reducing computational complexity. The NSL-KDD dataset is utilized to evaluate the proposed approach across five traffic classes: Benign, Denial of Service (DoS), Probe, Remote-to-Local (R2L), and User-to-Root (U2R). XGBoost feature ranking is employed to identify thirteen highly relevant features for each attack category, thereby reducing data dimensionality and eliminating redundant attributes. The selected features are subsequently evaluated using six ML classifiers, namely LightGBM, Voting Classifier, CatBoost, Multi-Layer Perceptron (MLP), AdaBoost, and Stochastic Gradient Descent (SGD). Performance assessment is conducted using Precision, Recall, F1-Score, confusion matrices, and cross-validation analysis. Experimental results demonstrate that ensemble-based models, particularly CatBoost and LightGBM, achieve superior performance for majority attack classes such as DoS and Probe, while all classifiers exhibit challenges in detecting minority classes such as R2L and U2R due to severe class imbalance. Cross-validation results confirm the robustness and stability of the selected feature subsets across different attack categories. Furthermore, a computational complexity analysis highlights the suitability of the proposed framework for practical and resource-constrained ID environments. The findings emphasize the effectiveness of feature optimization in enhancing classification performance and provide valuable insights for the development of efficient and scalable IDS solutions.
Aman Jyoti, Maninder Singh, V. Banga et al.· Scientific Reports· 0 citations
The findings indicate that the RF–SVM hybrid model provides an effective and scalable solution for real-time intrusion detection in modern cybersecurity environments.
Esther J., Grace Phiri, Arockia Venice J.· International Journal of Dat...· 0 citations
With the increasing use of computer networks and internet services, network security becomes crucially important. The existing intrusion detection methods are based on signature analysis or rules, but these methods are inefficient against zero-day attacks and evolving cyber threats. In order to overcome the disadvantages of existing solutions, this study proposes a novel IDS framework with hybrid feature selection method and adaptive threshold optimization. The IDS under consideration uses the UNSW-NB15 dataset. First, the data pre-processing algorithms such as encoding, scaling and class balancing are used. Hybrid feature selection is then implemented by means of a combination of chi-squared filtering and Particle Swarm Optimization (PSO). Several supervised learning algorithms, including K-Nearest Neighbors, Decision Tree, Logistic Regression and Random Forest are used for training and testing. Moreover, Adaptive Threshold Testing Algorithm (ATTA) is applied for dynamic optimization of decision thresholds. The results show that this solution considerably increases IDS efficiency and decreases false positive rates.
Valli S P, Rifat A K, Shameem Sakinah· IRO Journal on Sustainable W...· 0 citations
A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.
Gaurav Kishor Saxena, Shambhu Dayal Sahu· International Journal of Cre...· 0 citations
With the proliferation of internet-connected infrastructures and the complexity of cyberattacks, cybersecurity and intelligent intrusion detection systems have become more and more critical. Intrusion detection datasets, however, are now highly imbalanced, and conventional machine learning models have become biased towards the majority of benign traffic, misclassifying minority attack classes. This paper introduces a Cost-Sensitive Forest (CS-Forest) approach to enhance the detection of minority attacks in the CSE-CIC-IDS2018 dataset. The proposed framework combines cost-sensitive learning, ensemble-based Random Forest classification, feature selection, and SHAP explainability analysis to boost the performance of intrusion detection and interpretability. Various machine learning algorithms such as Decision Tree, Random Forest, AdaBoost, and XGBoost were tested and compared based on accuracy, precision, recall, F1-score, ROC-AUC, false positive rate, and false negative rate. Experimental results proved that the proposed CS-Forest has excellent performance, with 99.81% accuracy, 99.55% recall, 99.61% F1-score, and 0.998 ROC-AUC, significantly enhancing the performance of minority attack detection and reduced false negatives. The framework learned meaningful and interpretable network traffic behaviors, which was also confirmed using SHAP analysis. The research suggests that future IDS systems should incorporate cost-sensitive learning and explainable AI techniques to ensure improved reliability, transparency, and deployment in the cybersecurity landscape.
Highly accurate systems for detecting threats in real time are needed urgently owing to the exponential growth in cloud-network systems and increasingly sophisticated attacks. The conventional security systems using rules and signatures are inadequate in the changing environment of cloud computing because of evolving attacks.The suggested framework represents an intelligent solution for detecting and classifying threats in cloud computing by using smart machine learning algorithms. An intelligent system will collect data related to cloud network traffic and extract the features, and then it will use the supervisory learning algorithm to classify the threats. The experimental assessment has been performed based on a cloud intrusion detection dataset that consists of various types of attacks including network intrusion, malware, phishing, and data exfiltration. The implemented model had a total classification accuracy of 99.98% that proved to be very reliable with regard to detection of threats in which there are few false positives as well as false negatives. The findings confirm the assertion that the proposed framework offers real-time, scalable and effective security protection that is applicable in contemporary cloud-networks.
Pallapati Solmon, Shaik Khuran Bi, Yerram Lokeshreddy et al.· 2026 4th International Confe...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.