Jadwal Sholat

Memuat jadwal sholat…

Computer Science editorial

Open AccessOA2025

Improving Detection Accuracy of Network Intrusions Using a Hybrid Network Intrusion Detection System Based on Isolation Forest and Random Forest Algorithms

This study proposes a hybrid intrusion detection system integrating Suricata with Isolation Forest and Random Forest to enhance detection of novel threats and reduce false positives. Experimental results demonstrate high accuracy on both simulated and benchmark datasets, offering a scalable framework for enterprise network security.
Ryan Wang; R. Avrianto· Jurnal Teknik Informatika (Jutif)· 2025· DOI 10.52436/1.jutif.2025.6.6.4694

The core problem

The increasing sophistication of cyberattacks has made network security a critical concern for organizations handling sensitive and large-scale data. Traditional intrusion detection systems (IDS) like Suricata rely on signature-based methods, which are effective against known threats but often fail to detect zero-day or evolving attacks. This limitation creates a pressing need for more adaptive and intelligent detection mechanisms. To address this gap, this research proposes a hybrid IDS that combines Suricata's real-time packet inspection and anomaly filtering with machine learning algorithms—Isolation Forest and Random Forest. The goal is to enhance detection of novel threats while reducing false positives, thereby improving overall security posture. The study contributes a scalable framework that integrates anomaly- and signature-based detection, with practical implications for enterprise-level networks and intelligent cybersecurity defenses.

Innovation

The proposed hybrid IDS operates in two stages: Suricata performs initial packet inspection and anomaly filtering, generating alerts for suspicious traffic. These alerts, along with raw network data, are pre-processed and fed into a machine learning pipeline. The pipeline employs Isolation Forest for unsupervised anomaly detection and Random Forest for supervised classification of known attack patterns. The models are trained on a combination of the CICIDS2017 dataset and simulated attack data generated in a controlled environment. Real-time network traffic is captured and processed to evaluate the system's performance. Key metrics include accuracy, precision, recall, and -score. The hybrid approach leverages the strengths of both signature-based and anomaly-based detection, aiming to detect unknown threats while minimizing false alarms. The architecture can be represented as follows:

This flow ensures that both known and novel attacks are identified with high accuracy.

Introduction
The increasing sophistication of cyberattacks has made network security a critical concern for organizations handling sensitive and large-scale data. Traditional intrusion detection systems (IDS) like Suricata rely on signature-based methods, which are effective against known threats but often fail to detect zero-day or evolving attacks. This limitation creates a pressing need for more adaptive and intelligent detection mechanisms. To address this gap, this research proposes a hybrid IDS that combines Suricata's real-time packet inspection and anomaly filtering with machine learning algorithms—Isolation Forest and Random Forest. The goal is to enhance detection of novel threats while reducing false positives, thereby improving overall security posture. The study contributes a scalable framework that integrates anomaly- and signature-based detection, with practical implications for enterprise-level networks and intelligent cybersecurity defenses.

Why it matters

The findings underscore the advantages of integrating machine learning with traditional signature-based IDS. The hybrid model addresses key limitations of standalone systems: it improves detection of zero-day attacks and reduces false positives, which are common in anomaly-based systems. The use of Isolation Forest for unsupervised anomaly detection and Random Forest for supervised classification creates a complementary effect, where each algorithm compensates for the other's weaknesses. The high accuracy on both simulated and benchmark datasets suggests that the model generalizes well across different network environments. However, the study also acknowledges potential challenges, such as computational overhead and the need for continuous model updates to adapt to new threats. Future work could explore deep learning techniques and real-time deployment in large-scale enterprise networks. Overall, this research advances the field of network security by providing a scalable and adaptive IDS framework that combines signature- and anomaly-based detection, offering practical implications for intelligent cybersecurity defenses.

Who should read this

Pembaca Research Digest dan praktisi rumpun ini.

Opening member content…