Computer Science editorial
Improving Detection Accuracy of Network Intrusions Using a Hybrid Network Intrusion Detection System Based on Isolation Forest and Random Forest Algorithms
The core problem
Innovation
The proposed hybrid IDS operates in two stages: Suricata performs initial packet inspection and anomaly filtering, generating alerts for suspicious traffic. These alerts, along with raw network data, are pre-processed and fed into a machine learning pipeline. The pipeline employs Isolation Forest for unsupervised anomaly detection and Random Forest for supervised classification of known attack patterns. The models are trained on a combination of the CICIDS2017 dataset and simulated attack data generated in a controlled environment. Real-time network traffic is captured and processed to evaluate the system's performance. Key metrics include accuracy, precision, recall, and -score. The hybrid approach leverages the strengths of both signature-based and anomaly-based detection, aiming to detect unknown threats while minimizing false alarms. The architecture can be represented as follows:
This flow ensures that both known and novel attacks are identified with high accuracy.
Why it matters
Who should read this
Opening member content…