Intrusion Detection with Network Traffic ML
1. Key Characteristics of Network Traffic Data
Key Characteristics of Network Traffic Data
Statistical Properties
Network traffic exhibits distinct statistical properties that differentiate normal behavior from anomalies. Packet arrival times often follow a Poisson process, where the probability of k arrivals in a time interval t is given by:
Here, λ represents the average arrival rate. However, modern traffic often deviates from pure Poisson behavior due to burstiness, modeled more accurately by heavy-tailed distributions like Pareto or Weibull. The Hurst parameter H quantifies long-range dependence:
where R(n) is the range of cumulative deviations, S(n) is the standard deviation, and c is a constant. Values of H > 0.5 indicate persistent traffic patterns.
Feature Space Composition
Effective intrusion detection requires constructing a feature space capturing traffic dynamics. Key dimensions include:
- Temporal features: Inter-packet delays, flow duration, packets/second
- Volume metrics: Byte counts, packet sizes (mean/variance)
- Protocol composition: TCP/UDP ratios, ICMP prevalence
- Behavioral signatures: Port scanning frequency, SYN flood indicators
For encrypted traffic (e.g., TLS), features shift to observable metadata like:
- Handshake timing patterns
- Certificate chain characteristics
- Packet length entropy
Dimensionality Challenges
Raw network data in enterprise environments typically exceeds 100+ dimensions per flow. Principal Component Analysis (PCA) reduces dimensionality while preserving detection capability. The eigenvalue decomposition:
where Σ is the covariance matrix, W contains eigenvectors, and Λ is a diagonal matrix of eigenvalues. Retaining components explaining 95% variance often reduces dimensions by 10x while maintaining <2% false negative rates.
Concept Drift
Network traffic characteristics evolve due to:
- Application protocol updates (HTTP/2 → HTTP/3)
- Encryption standards migration (TLS 1.2 → 1.3)
- Emerging attack vectors (zero-day exploits)
Online learning methods like Adaptive Random Forests handle drift by dynamically updating decision trees based on the Hoeffding bound:
where R is the feature range, δ the confidence level, and n the sample count. This ensures model adaptation while controlling false positive growth.

Common Types of Network Intrusions and Attacks
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) Attacks
DoS and DDoS attacks aim to overwhelm a target system's resources, rendering it unavailable to legitimate users. A DoS attack originates from a single source, while a DDoS attack leverages a botnet—a network of compromised devices—to amplify the attack. The mathematical model for resource exhaustion can be expressed as:
Here, R(t) represents the resource consumption at time t, λi(t) is the arrival rate of malicious requests from the ith source, and τi is the processing time per request. When R(t) exceeds the system's capacity C, service degradation occurs.
Man-in-the-Middle (MitM) Attacks
MitM attacks involve an adversary intercepting and potentially altering communications between two parties. Common techniques include ARP spoofing, DNS spoofing, and SSL stripping. The success probability PMitM of such an attack depends on the encryption strength and network topology:
Where pi represents the probability of compromising the ith communication channel, and k is the total number of channels.
Port Scanning and Reconnaissance
Attackers perform port scanning to identify vulnerable services running on a target system. A stealthy scan may use TCP SYN packets without completing the handshake, mathematically modeled as:
Where S is the set of open ports, P is the total port space, and state(p) represents the response from port p.
SQL Injection and Cross-Site Scripting (XSS)
These web-based attacks exploit input validation flaws. SQL injection manipulates database queries, while XSS injects malicious scripts into web pages. The attack surface A can be quantified as:
Where wi is the weight of the ith input vector, and vi is its vulnerability score.
Zero-Day Exploits
These attacks target previously unknown vulnerabilities. The risk R0day depends on the time Δt between vulnerability introduction and patch deployment:
Where λ(t) is the time-dependent exploit likelihood function.
Advanced Persistent Threats (APTs)
APTs are prolonged, targeted attacks often involving multiple intrusion vectors. The compromise progression can be modeled as a Markov chain with states representing different attack stages and transition probabilities reflecting the attacker's success rates at each step.
Data Sources and Collection Methods for Network Traffic
Network Traffic Data Sources
Network traffic data for intrusion detection systems (IDS) is primarily sourced from three key modalities: packet captures (PCAP), flow-based records (NetFlow, sFlow), and log files from network devices. Each source provides distinct granularity and computational trade-offs.
- Packet Captures (PCAP): Provide full packet-level visibility, including headers and payloads, enabling deep inspection at the cost of storage and processing overhead. Tools like Wireshark and tcpdump collect PCAP data.
- Flow Records: Summarize traffic statistics (e.g., source/destination IPs, ports, byte counts) with lower storage requirements. Cisco NetFlow and IPFIX are industry standards.
- Device Logs: Firewalls, routers, and proxies generate logs with security-relevant events (e.g., blocked connections, authentication attempts).
Collection Methodologies
Network traffic collection strategies must balance fidelity with resource constraints. The optimal approach depends on the detection objectives:
1. Passive Monitoring
Passive taps or span ports mirror traffic without affecting network performance. This is implemented via:
- Hardware Taps: Physical devices that duplicate traffic at line rate for critical links.
- Switch SPAN Ports: Configured to mirror traffic from selected switch ports to a monitoring interface.
2. Active Probing
Active methods inject test traffic to measure network response characteristics. Techniques include:
- ICMP Ping Sweeps: Detect live hosts and latency variations.
- Traceroute Analysis: Map network paths and identify routing anomalies.
Traffic Sampling Techniques
For high-speed networks, sampling is essential to reduce data volume while preserving detection accuracy. Common methods include:
Where n is the sampled packet count and N is the total traffic volume. Adaptive sampling algorithms dynamically adjust rates based on:
- Flow entropy changes
- Anomaly score thresholds
- Available computational resources
Feature Extraction Pipeline
Raw network data undergoes transformation into machine learning features through:
- Packet-Level Features: Protocol flags, payload sizes, inter-arrival times.
- Flow Aggregations: Duration, byte/packet counts, jitter statistics.
- Behavioral Metrics: Entropy of destination IPs, port scanning patterns.
Public Datasets for Benchmarking
Several curated datasets enable reproducible research in network intrusion detection:
- CIC-IDS2017: Contains labeled attacks (Brute Force, XSS, DDoS) with full packet captures and NetFlow records.
- UNSW-NB15: Combines synthetic and real traffic with nine attack categories.
- MAWI Dataset: Long-term internet backbone traces with ground truth labels.

2. Supervised Learning Techniques for Classification
Supervised Learning Techniques for Classification
Foundations of Supervised Classification
Supervised learning for network intrusion detection relies on labeled datasets where each traffic sample is annotated as normal or malicious. Given a feature vector x ∈ ℝd (e.g., packet size, protocol type, flow duration), the goal is to learn a decision function f: ℝd → {0,1} that minimizes the empirical risk:
where ℒ is a loss function (e.g., cross-entropy), Ω(f) is a regularization term, and λ controls model complexity. For imbalanced intrusion datasets, weighted loss functions or resampling techniques are often employed.
Key Algorithms and Their Adaptations
1. Support Vector Machines (SVMs)
SVMs construct a hyperplane w·x + b = 0 that maximizes the margin between classes. The dual optimization problem for non-linear separation via kernel K is:
subject to 0 ≤ αi ≤ C and ∑αiyi = 0. Radial Basis Function (RBF) kernels are particularly effective for capturing complex traffic patterns.
2. Random Forests
An ensemble of T decision trees, each trained on a bootstrap sample with random feature subsets. The final prediction aggregates votes via:
Feature importance scores derived from Gini impurity reductions help identify critical network indicators (e.g., SYN flood rates).
Deep Learning Approaches
Multi-layer perceptrons (MLPs) with architectures like:
model = Sequential([
Dense(128, activation='relu', input_shape=(n_features,)),
Dropout(0.5),
Dense(64, activation='relu'),
Dense(1, activation='sigmoid')
])
model.compile(loss='binary_crossentropy', optimizer='adam', metrics=['AUC'])
achieve state-of-the-art performance when trained on engineered features (e.g., time-window statistics). Temporal patterns are better captured by LSTM networks processing sequential packet data.
Evaluation Metrics for Imbalanced Data
Traditional accuracy is misleading for intrusion detection where attack rates may be <1%. Instead, use:
- Precision-Recall AUC: Robust to class imbalance
- Fβ: Weighted harmonic mean (β > 1 emphasizes recall)
- Matthews Correlation Coefficient: Accounts for all confusion matrix entries
Unsupervised Learning for Anomaly Detection
Unsupervised learning techniques are critical for identifying anomalies in network traffic where labeled data is scarce or nonexistent. These methods rely on the intrinsic structure of the data to detect deviations without prior knowledge of attack signatures. Key algorithms include clustering, density estimation, and autoencoders, each offering distinct advantages for different types of network behavior.
Clustering-Based Anomaly Detection
Clustering algorithms group similar data points, treating outliers as anomalies. K-means and DBSCAN are widely used in intrusion detection due to their scalability and interpretability. K-means partitions data into k clusters by minimizing intra-cluster variance:
where Ci represents cluster i, and μi is its centroid. Points far from any centroid are flagged as anomalies. DBSCAN, in contrast, identifies dense regions and marks sparse regions as outliers, making it robust to varying cluster shapes.
Density Estimation with Gaussian Mixture Models
Gaussian Mixture Models (GMMs) approximate the probability distribution of normal traffic. The likelihood of a sample x is given by:
where ϕi are mixture weights, and μi, Σi are the mean and covariance of each Gaussian component. Samples with low probability under the GMM are classified as anomalies. Expectation-Maximization (EM) is typically used for parameter estimation.
Autoencoders for Nonlinear Feature Extraction
Autoencoders learn compressed representations of normal traffic and reconstruct input data with minimal error. Anomalies induce high reconstruction errors due to their deviation from the training distribution. The loss function for an autoencoder with encoder f and decoder g is:
Variants like Variational Autoencoders (VAEs) and Denoising Autoencoders improve robustness by modeling latent distributions or corrupting inputs during training.
Isolation Forests for High-Dimensional Data
Isolation Forests exploit the fact that anomalies are few and different, making them easier to isolate with random splits. The algorithm builds an ensemble of isolation trees, where the average path length to isolate a sample indicates its anomaly score:
Here, h(x) is the path length, and c(n) normalizes for tree size. Scores close to 1 indicate anomalies.
Practical Considerations
- Feature Engineering: Network traffic features (e.g., packet size, protocol, flow duration) must capture attack patterns.
- Scalability: Online algorithms like Streaming K-means adapt to evolving traffic.
- Evaluation: Metrics like precision-recall curves and F1-score account for class imbalance.

2.3 Hybrid and Ensemble Methods
Hybrid and ensemble methods combine multiple machine learning models to improve intrusion detection accuracy, robustness, and generalization. Unlike single-model approaches, these techniques leverage the strengths of diverse algorithms to mitigate individual weaknesses, particularly in handling imbalanced datasets and adversarial evasion tactics.
Hybrid Methods
Hybrid methods integrate complementary techniques—such as unsupervised clustering followed by supervised classification—to enhance detection performance. A common approach involves using autoencoders for anomaly detection and feeding the latent representations into a classifier like Random Forest or XGBoost for final decision-making. The hybrid model's effectiveness stems from its ability to capture both global patterns (via clustering) and local discriminative features (via classification).
where Lrecon is the reconstruction loss from the autoencoder, Lclass is the classification loss, and α balances their contributions.
Ensemble Methods
Ensemble methods aggregate predictions from multiple base learners to reduce variance and bias. Key techniques include:
- Bagging (Bootstrap Aggregating): Trains multiple instances of the same model (e.g., Decision Trees) on different subsets of the training data, then averages predictions. Effective for high-variance models.
- Boosting: Iteratively trains weak learners (e.g., shallow Decision Trees) by focusing on misclassified samples. Algorithms like AdaBoost and Gradient Boosting Machines (GBM) adjust sample weights dynamically.
- Stacking: Combines heterogeneous models (e.g., SVM, Neural Networks) via a meta-learner that learns optimal weighting from their outputs.
The ensemble's final decision for a sample x can be expressed as:
where fi is the i-th base learner and wi its assigned weight.
Practical Implementation
For network intrusion detection, a robust ensemble might combine:
- A One-Class SVM for outlier detection in unlabeled traffic.
- A Gradient Boosted Tree for supervised classification of known attack signatures.
- A Deep Neural Network for temporal pattern recognition in packet sequences.
Feature importance analysis often reveals that ensemble models prioritize:
- Flow duration and packet size statistics for volumetric attacks (DDoS).
- TCP flag distributions for probing/scans.
- Payload entropy for encrypted or obfuscated malware.
Case Study: Adaptive Boosting for Zero-Day Attacks
In a 2023 study, an AdaBoost-based detector achieved 98.2% F1-score on the CIC-IDS2017 dataset by iteratively refining its focus on hard-to-classify samples. The model's weighted voting mechanism proved particularly effective against novel attack vectors lacking clear signatures.
from sklearn.ensemble import AdaBoostClassifier
from sklearn.tree import DecisionTreeClassifier
base_estimator = DecisionTreeClassifier(max_depth=1)
adaboost = AdaBoostClassifier(
estimator=base_estimator,
n_estimators=50,
learning_rate=0.8
)
adaboost.fit(X_train, y_train)

3. Feature Extraction from Network Traffic
3.1 Feature Extraction from Network Traffic
Effective intrusion detection systems rely on robust feature extraction techniques to transform raw network traffic into meaningful representations for machine learning models. Network traffic data is inherently high-dimensional and noisy, necessitating careful preprocessing to isolate discriminative patterns indicative of malicious activity.
Statistical Feature Engineering
Packet-level and flow-based statistics serve as foundational features for intrusion detection. For a given network flow F consisting of n packets, the following temporal and volumetric features are commonly extracted:
where ti represents inter-arrival times between consecutive packets. These metrics capture timing patterns that often distinguish benign traffic from attacks like port scanning or DDoS.
Protocol-Specific Feature Extraction
Transport layer protocols exhibit distinct behavioral signatures. For TCP flows, features include:
- SYN/ACK ratio anomalies
- Window size volatility
- Retransmission rate
- Connection duration outliers
UDP-based attacks require different feature sets, focusing on:
- Packet size distribution skewness
- Source port entropy
- Payload uniformity metrics
Payload Content Analysis
Deep packet inspection enables extraction of application-layer features through:
where H(p) computes byte-level entropy for detecting encrypted or obfuscated payloads. Combined with n-gram analysis, this reveals malware command patterns and exploit signatures.
Graph-Based Network Representations
Host communication patterns form temporal graphs where edges weight represents flow characteristics. Graph convolutional networks operate on adjacency matrices A constructed as:
with edge weights wij encoding traffic volume, protocol mix, or connection frequency.
Time-Series Feature Extraction
Sliding window approaches generate sequential features for recurrent models. For a window size w, autocorrelation coefficients reveal periodic attack patterns:
where k represents the time lag parameter. Wavelet transforms further decompose traffic bursts across timescales.

3.2 Handling Imbalanced Datasets
Imbalanced datasets in network intrusion detection pose significant challenges, as malicious traffic often constitutes a tiny fraction of overall network activity. Traditional classifiers tend to favor the majority class, leading to poor detection rates for rare attack types. Advanced techniques must be employed to mitigate this bias.
Resampling Techniques
Resampling adjusts class distribution by either oversampling the minority class or undersampling the majority class. For intrusion detection, oversampling is generally preferred to avoid losing critical attack patterns.
- SMOTE (Synthetic Minority Oversampling Technique) generates synthetic samples by interpolating between existing minority instances. Given a sample x from the minority class, SMOTE selects k nearest neighbors and creates new instances:
where λ is a random number between 0 and 1, and xnn is a randomly chosen neighbor.
- ADASYN (Adaptive Synthetic Sampling) extends SMOTE by focusing on difficult-to-learn minority samples, generating more synthetic data near decision boundaries.
Algorithmic Approaches
Modifying the learning algorithm itself can effectively handle class imbalance:
- Cost-sensitive learning assigns higher misclassification costs to minority classes. For a binary classifier with classes y ∈ {0,1}, the cost matrix C modifies the loss function:
where ℓ is the base loss function and Ci,j represents the cost of predicting class j when the true class is i.
- Ensemble methods like Balanced Random Forest and EasyEnsemble combine multiple undersampled datasets with bagging to maintain diversity while addressing imbalance.
Evaluation Metrics for Imbalanced Data
Accuracy becomes meaningless with severe class imbalance. Instead, use:
- Precision-Recall curves, particularly Area Under the Curve (AUC-PR)
- Fβ-score that balances precision and recall:
where β controls the relative importance of recall versus precision (typically β > 1 for intrusion detection).
Deep Learning Approaches
Neural networks can leverage:
- Class-weighted loss functions that scale the contribution of each class to the total loss inversely proportional to class frequency
- Focal loss, which down-weights well-classified examples to focus on hard negatives:
where pt is the model's estimated probability for the true class, γ focuses learning on hard examples, and αt balances class importance.

3.3 Dimensionality Reduction Techniques
High-dimensional network traffic data often contains redundant or correlated features, complicating intrusion detection models. Dimensionality reduction techniques mitigate this by projecting data into a lower-dimensional space while preserving discriminative information. Two principal approaches dominate: feature selection and feature extraction.
Principal Component Analysis (PCA)
PCA identifies orthogonal directions of maximum variance in the data. Given a centered dataset X with n samples and d features, the covariance matrix C is computed as:
Eigenvalue decomposition yields principal components (eigenvectors) sorted by explained variance (eigenvalues). For intrusion detection, retaining components capturing 95% cumulative variance typically balances information retention and dimensionality reduction. The projection of data onto the top-k components is:
where Wk contains the first k eigenvectors. PCA assumes linearity and Gaussian distributions, which may not hold for raw network traffic.
t-Distributed Stochastic Neighbor Embedding (t-SNE)
t-SNE optimizes a nonlinear mapping that preserves local pairwise similarities in high-dimensional space. It converts Euclidean distances between points xi and xj into conditional probabilities:
A Student-t distribution in the low-dimensional space avoids crowding. The Kullback-Leibler divergence between the high- and low-dimensional distributions is minimized via gradient descent. t-SNE excels at visualizing clusters of attack patterns but scales poorly to large datasets.
Autoencoder-Based Reduction
Autoencoders learn compressed representations through a bottleneck layer. The encoder fθ and decoder gϕ are trained to minimize reconstruction loss:
Variants like denoising autoencoders or variational autoencoders improve robustness. For network traffic, convolutional or recurrent layers capture spatial/temporal dependencies. The latent space often reveals discriminative features for anomaly detection.
Feature Selection via Mutual Information
Mutual information measures nonlinear dependencies between features and labels. For discrete features X and class labels Y:
Kernel density estimation extends this to continuous features. Selecting top-k features maximizes relevance while minimizing redundancy. Compared to PCA, this preserves interpretability—critical for forensic analysis of intrusions.
Comparative Performance in Intrusion Detection
On the CIC-IDS2017 dataset, PCA reduces 80 features to 15 while maintaining 99% detection accuracy in Random Forest models. t-SNE reveals distinct clusters for brute-force and DDoS attacks in 2D visualizations. Autoencoders achieve 7% higher F1-score than PCA on zero-day attacks by learning traffic-specific embeddings. Mutual information selects 20% fewer features than correlation-based methods without sacrificing precision.

4. Performance Metrics for Intrusion Detection Systems
Performance Metrics for Intrusion Detection Systems
Evaluating the effectiveness of an intrusion detection system (IDS) requires a rigorous set of performance metrics. Unlike generic classification tasks, IDS must account for severe class imbalance, high false positive costs, and adversarial evasion attempts. The following metrics provide a comprehensive assessment of IDS performance in real-world network environments.
Confusion Matrix-Based Metrics
The confusion matrix forms the foundation for most IDS evaluation metrics. For binary classification (normal vs. malicious traffic), it consists of:
- True Positives (TP): Malicious samples correctly classified
- False Positives (FP): Normal samples incorrectly flagged as malicious
- True Negatives (TN): Normal samples correctly classified
- False Negatives (FN): Malicious samples missed
From these, we derive critical security metrics:
Composite Metrics
Single metrics often fail to capture the trade-offs in IDS performance. Composite metrics balance multiple aspects:
The Fβ score generalizes this for security applications where recall is β times more important than precision:
Cost-Sensitive Metrics
IDS deployments require cost matrices that account for operational realities. The expected cost C is:
Where CFP and CFN represent organization-specific costs of false positives and false negatives respectively.
ROC and Precision-Recall Analysis
Receiver Operating Characteristic (ROC) curves plot TPR against FPR across decision thresholds, with Area Under Curve (AUC) providing a threshold-independent performance measure. For imbalanced IDS datasets (often <1% attack prevalence), Precision-Recall curves often provide more discriminative analysis.
Advanced Metrics for IDS
Modern IDS evaluation incorporates additional dimensions:
- Evasion Resistance: Measured through adversarial testing with mutated attack patterns
- Alert Fatigue Score: Quantifies operator burden from excessive false alarms
- Time-to-Detection: Critical for advanced persistent threat scenarios
- Concept Drift Resilience: Measures performance degradation over time as attack patterns evolve
Benchmarking Considerations
Proper IDS evaluation requires:
- Representative test sets matching real network traffic distributions
- Separate validation of known and zero-day attack detection
- Testing under realistic network throughput conditions
- Comparison against baseline methods (Snort, Suricata rules)

4.2 Cross-Validation Strategies
Cross-validation is a critical technique for evaluating machine learning models, particularly in intrusion detection systems where data imbalance and concept drift are common. Unlike a single train-test split, cross-validation provides a robust estimate of model performance by partitioning the dataset into multiple folds, ensuring that every data point is used for both training and validation.
K-Fold Cross-Validation
The most widely used method, k-fold cross-validation, divides the dataset into k equally sized folds. The model is trained on k-1 folds and validated on the remaining fold, repeating this process k times. The final performance metric is the average across all folds. For network traffic data, this mitigates bias from temporal dependencies or uneven attack distributions.
Choosing k involves a trade-off: smaller k (e.g., 5) reduces computational cost but increases variance, while larger k (e.g., 10) improves stability at higher computational expense. Stratified k-fold is preferred for imbalanced datasets, preserving the class distribution in each fold.
Time Series Cross-Validation
Network traffic exhibits temporal dependencies, making standard k-fold unsuitable. Time series cross-validation ensures chronological order is maintained. In rolling-window validation, the training set expands incrementally while the test set slides forward:
This mirrors real-world deployment where models predict future attacks based on historical data. The gap parameter can be introduced to simulate detection latency.
Nested Cross-Validation
For hyperparameter tuning without data leakage, nested cross-validation employs two loops: an outer loop for performance estimation and an inner loop for model selection. The outer loop splits data into training and test sets, while the inner loop performs k-fold on the training set to optimize hyperparameters.
This method is computationally intensive but essential for unbiased evaluation in intrusion detection, where overfitting to specific attack patterns is a risk.
Leave-One-Out Cross-Validation (LOOCV)
A special case of k-fold where k = n (number of samples). Each iteration uses a single sample for validation and the rest for training. While theoretically optimal for small datasets, LOOCV is rarely practical for network traffic due to high computational cost and minimal performance gain over 10-fold.
Bootstrapping
An alternative to k-fold, bootstrapping generates multiple datasets by sampling with replacement. The model is trained on bootstrap samples and evaluated on out-of-bag (OOB) data. The .632 estimator corrects for bias:
Useful for highly imbalanced datasets, but may underestimate variance compared to k-fold.
Practical Considerations for Network Traffic
- Stratification: Ensure each fold contains representative samples of rare attacks.
- Concept Drift: Use time-aware splits or sliding windows to simulate evolving threats.
- Computational Efficiency: Parallelize folds for large-scale traffic logs.

4.3 Addressing False Positives and False Negatives
In intrusion detection systems, the trade-off between false positives (benign traffic flagged as malicious) and false negatives (malicious traffic undetected) represents a fundamental challenge. The optimal operating point depends on the security context - where false negatives may be catastrophic in high-security environments, while false positives degrade usability in enterprise networks.
Mathematical Formulation of Detection Trade-offs
The relationship between false positives and false negatives is formally captured in the receiver operating characteristic (ROC) curve, which plots the true positive rate (TPR) against false positive rate (FPR) across different decision thresholds. The area under the ROC curve (AUC) quantifies overall detector performance:
For network intrusion detection, we often optimize the Fβ-score that balances precision and recall, where β controls the relative importance of false negatives:
Advanced Techniques for Mitigation
Cost-Sensitive Learning
Traditional machine learning assumes equal misclassification costs. Cost-sensitive methods explicitly incorporate asymmetric penalties:
Where C(y,ŷ) represents the cost matrix, L is the loss function, and R(w) is the regularization term. In network security, typical cost ratios range from 1:10 to 1:1000 for false negatives vs false positives.
Ensemble Methods with Rejection
Hybrid architectures combine multiple detectors with a rejection option when confidence is low. The reject region R is defined as:
Where pj(x) is the estimated probability from classifier j, and θ is the rejection threshold. Samples in R undergo additional verification through secondary checks or human analysis.
Real-World Implementation Considerations
Operational systems require dynamic threshold adjustment based on:
- Time-varying attack patterns: Adaptive thresholds using exponentially weighted moving averages of recent FPR/FNR
- Network context: Different thresholds for DMZ vs internal segments
- Alert fatigue management: Progressive threshold relaxation during high-volume periods
The optimal operating point can be determined through multi-objective optimization:
Where α and β represent organizational risk tolerances. Pareto front analysis helps identify non-dominated solutions.
Case Study: Cloud Provider Implementation
A major cloud provider reduced false positives by 62% while maintaining detection rates through:
- Hierarchical classification with coarse-to-fine filtering
- Online learning to adapt to new traffic patterns
- Feedback loops from security operations center
Their implementation uses an ensemble of LSTM autoencoders for anomaly detection coupled with random forests for signature-based detection, with dynamic weighting based on recent performance metrics.

5. Scalability and Real-Time Processing
5.1 Scalability and Real-Time Processing
Challenges in High-Throughput Network Traffic Analysis
Modern networks generate traffic at rates exceeding terabits per second, requiring intrusion detection systems (IDS) to process millions of packets per second with sub-millisecond latency. Traditional batch-processing machine learning models fail under these conditions due to:
- Memory bottlenecks: Storing raw packet data for offline analysis becomes infeasible at scale.
- Computational complexity: Feature extraction and inference must complete within packet arrival intervals.
- Concept drift: Attack patterns evolve faster than batch retraining cycles.
Stream Processing Architectures
Real-time IDS implementations leverage stream processing frameworks with these key components:
Where λmin is the minimum sustainable packet rate, Tfeat is feature extraction time, and Tinf is inference time. Achieving wire-speed processing requires:
- Parallel feature extraction: Distributing flow segmentation across GPU/FPGA accelerators
- Model quantization: Reducing neural network precision to INT8 without significant accuracy loss
- Incremental learning: Online algorithms like Adaptive Random Forests that update without full retraining
Distributed Feature Engineering
Time-critical features must be computed in sliding windows with constant memory overhead. For TCP flow analysis:
Where w is the window size, |pkti| is packet length, τi is inter-arrival time, and 𝕀 is an indicator function. This can be computed recursively:
Hardware Acceleration
Three architectural approaches dominate high-performance implementations:
| Approach | Throughput | Latency | Flexibility |
|---|---|---|---|
| GPU Pipelines | 100-400 Gbps | 50-200μs | High |
| FPGA Logic | 200-600 Gbps | 10-50μs | Medium |
| ASIC Designs | 1+ Tbps | <5μs | Low |
Hybrid designs using SmartNICs with programmable data planes (e.g., P4 language) achieve balance between performance and adaptability.
Online Learning Strategies
Concept drift adaptation requires continuous model updates. The Drift Detection Method (DDM) triggers retraining when:
Where pt is current error rate and σt its standard deviation. Efficient implementations use:
- Reservoir sampling: Maintaining fixed-size representative buffers
- Ensemble pruning: Dynamically adding/removing detectors
- Transfer learning: Preserving feature extractors while updating classifiers

5.2 Adapting to Evolving Threats
Traditional intrusion detection systems (IDS) often fail to keep pace with rapidly evolving cyber threats due to their reliance on static rule-based signatures. Machine learning (ML) offers a dynamic alternative by enabling models to adapt to new attack patterns through continuous learning. However, achieving robust adaptability requires addressing several key challenges, including concept drift, adversarial attacks, and real-time model updating.
Concept Drift in Network Traffic
Network traffic distributions shift over time due to changes in user behavior, software updates, and emerging attack vectors. This phenomenon, known as concept drift, degrades the performance of static ML models. Formally, concept drift occurs when the joint probability distribution of features and labels changes:
where X represents network traffic features and y denotes the intrusion labels at time t. Detecting and adapting to drift requires:
- Statistical tests like Kolmogorov-Smirnov or CUSUM to identify distribution shifts
- Window-based approaches that compare model performance across time intervals
- Online learning algorithms that incrementally update model parameters
Adversarial Robustness
Attackers actively attempt to evade detection by crafting adversarial network traffic that mimics benign behavior. Let x be a malicious traffic sample and η be an adversarial perturbation designed to fool the classifier f:
Defending against such attacks involves:
- Adversarial training: Augmenting the training set with perturbed examples
- Input sanitization: Detecting and removing suspicious feature manipulations
- Ensemble methods: Combining multiple detectors to increase robustness
Continuous Learning Architectures
Effective adaptation requires architectures that support seamless model updates without catastrophic forgetting of previous knowledge. Three primary approaches have shown promise:
- Elastic Weight Consolidation (EWC): Preserves important parameters when learning new tasks
- Memory Replay: Stores and periodically retrains on historical data
- Modular Networks: Adds new expert modules for novel threats while maintaining core functionality
The following equation illustrates EWC's regularization term that protects critical parameters θi during updates, where Fi represents their Fisher information importance:
Real-World Implementation Challenges
Deploying adaptive IDS in production environments introduces additional constraints:
- Latency requirements: Model updates must complete within operational time windows
- Resource efficiency: Algorithms must run on available hardware without excessive compute/memory
- Explainability: Security teams require interpretable alerts to investigate potential threats
Recent advances in edge computing and federated learning enable distributed adaptation where local models learn from regional traffic patterns while periodically synchronizing with a global model. This architecture balances adaptability with privacy preservation by keeping sensitive network data localized.

5.3 Integration with Existing Security Infrastructure
Integrating machine learning-based intrusion detection systems (ML-IDS) with legacy security infrastructure requires careful consideration of data flow, latency constraints, and compatibility with existing protocols. The primary challenge lies in ensuring real-time processing without disrupting network performance while maintaining interoperability with firewalls, SIEMs, and endpoint protection platforms.
Data Pipeline Architecture
ML-IDS relies on high-throughput ingestion of network traffic features, typically extracted from NetFlow, sFlow, or raw packet captures. A scalable pipeline involves:
- Preprocessing Layer: Normalizes heterogeneous data sources (e.g., converting PCAP to flow records) using tools like Apache NiFi or Kafka Streams.
- Feature Store: Maintains temporal consistency of engineered features (e.g., packet inter-arrival times, entropy of payload bytes) for both training and inference.
- Model Serving: Deploys trained models via TensorFlow Serving or ONNX Runtime, with gRPC/HTTP APIs for low-latency inference.
where τsys represents total system latency, τpreprocess and τinference are processing times, and μqueue is the message queue throughput.
Protocol Compatibility
Legacy security tools often use standardized protocols for alert dissemination:
- SIEM Integration: ML-IDS outputs must map to Common Event Format (CEF) or Structured Threat Information Expression (STIX) for correlation in Splunk or IBM QRadar.
- Firewall Coordination: Dynamic rule updates via REST APIs (e.g., Palo Alto Panorama) require idempotent operations to prevent race conditions.
Case Study: Suricata + TensorFlow
A hybrid deployment might use Suricata's EVE JSON output as input to an LSTM model, with alerts forwarded via Syslog-ng. The critical path involves:
- Packet capture at line rate using PF_RING or DPDK
- Real-time feature extraction (e.g., TLS handshake analysis)
- Inference on GPU-accelerated edge devices
Performance Optimization
To minimize latency in high-speed networks (≥100Gbps), consider:
- Hardware Offloading: SmartNICs (e.g., NVIDIA BlueField) can handle feature extraction at line rate.
- Model Compression: Quantizing neural networks to INT8 precision reduces inference time by 3× with minimal accuracy loss.
- Load Balancing: Consistent hashing of flow tuples across multiple inference workers maintains session state.
# Example gRPC model server for CEF-compatible alerts
import grpc
from concurrent import futures
from proto import ids_pb2, ids_pb2_grpc
class IDSServicer(ids_pb2_grpc.IDSServiceServicer):
def Predict(self, request, context):
features = preprocess(request.flow_data)
prediction = model.predict(features)
return ids_pb2.Alert(
severity=map_score_to_cef(prediction),
signature="ML-Detected Anomaly"
)
server = grpc.server(futures.ThreadPoolExecutor(max_workers=8))
ids_pb2_grpc.add_IDSServiceServicer_to_server(IDSServicer(), server)
server.add_insecure_port('[::]:50051')
server.start()

6. Enterprise Network Security
Enterprise Network Security
Enterprise networks face sophisticated cyber threats that demand robust intrusion detection systems (IDS) capable of analyzing high-dimensional traffic data in real time. Machine learning (ML) models excel in this domain by identifying anomalous patterns that evade rule-based detection. Unlike traditional signature-based methods, ML-driven IDS adapt to evolving attack vectors by learning from historical traffic behavior.
Feature Engineering for Network Traffic
Raw network packets contain redundant and noisy data, necessitating feature extraction to improve model performance. Key statistical features include:
- Packet-level metrics: Inter-arrival times, payload sizes, protocol distributions.
- Flow-based aggregates: Duration, bytes transmitted, packet counts per flow.
- Behavioral signatures: Entropy of destination ports, connection fan-out rates.
For a traffic flow F with n packets, the entropy H of destination ports is computed as:
where pi is the probability of observing port i in the flow. High entropy indicates scan attempts or worm propagation.
Deep Learning Architectures for Anomaly Detection
Convolutional Neural Networks (CNNs) process spatial hierarchies in traffic matrices, while Long Short-Term Memory (LSTM) networks model temporal dependencies in flow sequences. A hybrid architecture combines both:
where Wc denotes CNN filters, X is the input traffic matrix, Wl are LSTM weights, and ht-1 is the previous hidden state. The CIC-IDS2017 dataset benchmarks show 98.2% F1-score for such models.
Adversarial Robustness
Attackers craft adversarial samples by perturbing packet headers to evade detection. Defensive distillation trains models to resist such attacks by smoothing decision boundaries:
where T is the temperature parameter. At T > 1, the softmax output becomes less sensitive to input perturbations.
Case Study: Zero-Day Ransomware Detection
A multinational bank deployed an ensemble of Isolation Forest and Autoencoder models to detect novel ransomware. The system triggered on:
- Sudden spikes in SMB protocol traffic (Isolation Forest anomaly score > 0.75).
- High file entropy in encrypted payloads (Autoencoder reconstruction error > 2σ).
This reduced false positives by 63% compared to Snort rules while maintaining 94% recall for zero-day variants.
Real-Time Deployment Challenges
Latency constraints require optimized feature extraction pipelines. NVIDIA Morpheus provides a GPU-accelerated framework for:
- Online feature normalization using exponentially weighted moving averages.
- Parallel inference across multiple ML models.
- Hardware-accelerated packet parsing via DPDK.
For a 40 Gbps link, this achieves 3.2 ms end-to-end latency with 256-byte packets.

6.2 Cloud-Based Intrusion Detection
Cloud-based intrusion detection systems (IDS) leverage distributed computing resources to analyze network traffic at scale, enabling real-time threat detection across geographically dispersed infrastructure. Unlike traditional on-premises IDS, cloud-native solutions integrate machine learning models with elastic scalability, reducing latency and computational bottlenecks.
Architecture of Cloud-Based IDS
A typical cloud-based IDS consists of three core components:
- Data ingestion layer: Collects raw network packets or flow data (NetFlow, sFlow) from virtual private clouds (VPCs), containers, and serverless functions through distributed agents or API gateways.
- Stream processing engine: Applies windowed analytics (e.g., Apache Flink, Spark Streaming) to extract features like packet entropy, flow duration, and protocol distributions in near real-time.
- Threat detection models: Deploys ensemble ML algorithms (isolation forests, autoencoders, or GAN-based anomaly detectors) as microservices in Kubernetes clusters.
Feature Engineering for Cloud Traffic
Cloud network traffic exhibits unique characteristics requiring specialized feature engineering:
Where φt computes the skewness of request inter-arrival times xi within time window t, with μt and σt as the window's mean and standard deviation. Other critical features include:
- API call graph anomalies (detected via graph neural networks)
- Cross-tenant communication patterns
- Cloud metadata API access frequencies
Model Deployment Strategies
Two dominant paradigms exist for deploying ML models in cloud IDS:
1. Centralized Inference
All feature vectors are routed to a regional inference endpoint. The latency penalty is offset by batch processing with:
Where λ is arrival rate, μ service rate, and CV the coefficient of variation.
2. Edge-Cloud Hybrid
Lightweight models (e.g., distilled neural networks) run at edge locations, while complex ensembles execute in central clouds. This reduces bandwidth usage by transmitting only suspicious flows for secondary verification.
Case Study: AWS GuardDuty
Amazon's managed threat detection service demonstrates key cloud IDS innovations:
- Uses VPC flow logs, CloudTrail events, and DNS queries as input streams
- Combines supervised learning (threat intelligence feeds) with unsupervised clustering
- Implements model retraining every 6 hours via SageMaker pipelines
Performance Optimization
Cloud IDS face unique challenges in model efficiency:
# TensorFlow Lite model quantization for edge deployment
converter = tf.lite.TFLiteConverter.from_saved_model(saved_model_dir)
converter.optimizations = [tf.lite.Optimize.DEFAULT]
converter.target_spec.supported_ops = [tf.lite.OpsSet.TFLITE_BUILTINS_INT8]
quantized_model = converter.convert()
Other techniques include:
- Network function virtualization (NFV) for elastic scaling
- Hardware-accelerated inference (AWS Inferentia, Google TPUs)
- Federated learning across cloud regions

6.3 IoT and Edge Device Protection
Securing IoT and edge devices against network intrusions presents unique challenges due to their constrained computational resources, heterogeneous communication protocols, and distributed deployment environments. Traditional intrusion detection systems (IDS) designed for cloud or enterprise networks are often infeasible for these devices, necessitating lightweight, adaptive machine learning (ML) approaches.
Resource-Constrained ML Model Optimization
Edge devices typically operate with limited memory, processing power, and energy budgets. Deploying conventional deep learning models is impractical, requiring techniques such as quantization, pruning, and knowledge distillation to reduce model complexity. For a neural network with weights W, quantization maps floating-point values to lower-bit integers:
where b is the target bit-width. Pruning removes redundant connections by zeroing out weights below a threshold τ:
where ⊙ denotes element-wise multiplication and 𝕀 is the indicator function. These optimizations can reduce model size by 80-90% with minimal accuracy loss.
Federated Learning for Distributed Threat Detection
Centralized training on IoT device data raises privacy and bandwidth concerns. Federated learning (FL) enables collaborative model training without raw data exchange. Devices compute local gradients on their datasets, which are aggregated by a central server:
where η is the learning rate, nk is the sample count for device k, and N is the total samples across all devices. Differential privacy can be added by injecting noise into the gradients before aggregation.
Real-Time Anomaly Detection Architectures
Streaming network traffic analysis demands low-latency inference. TinyML frameworks like TensorFlow Lite for Microcontrollers enable deployment of compact autoencoder models for anomaly detection. The reconstruction error ε for input x is computed as:
where E and D are the encoder and decoder networks. A moving average of errors triggers alerts when exceeding dynamically adjusted thresholds based on extreme value theory.
Protocol-Specific Feature Engineering
IoT networks use diverse protocols (MQTT, CoAP, Zigbee), each requiring tailored feature extraction. For MQTT traffic, key features include:
- Message rate per topic
- Payload entropy
- QoS level distribution
- Retained message ratio
CoAP features focus on message types (CON/NON), response codes, and block-wise transfer patterns. These protocol-aware features improve detection accuracy compared to generic network statistics.
Hardware-Assisted Security
Modern microcontrollers integrate Trusted Execution Environments (TEEs) and cryptographic accelerators. ML models can leverage these for:
- Secure model storage in encrypted flash
- Tamper-resistant inference execution
- Hardware-accelerated SHA-256 for model integrity checks
This hardware-software co-design approach provides defense against physical attacks while maintaining real-time performance constraints.

7. Key Research Papers and Publications
7.1 Key Research Papers and Publications
- Network intrusion detection system: A systematic study of machine ... — This paper provides an extensive review of the network intrusion detection mechanisms based on the ML and DL methods to provide the new researchers with the updated knowledge, recent trends, and progress of the field.
- Multi-layer perceptron for network intrusion detection — In IDS research, many papers cover the traditional approaches in depth while a smaller number of papers focus on neural network techniques. Our main contributions consist of four parts. First, we review and compare two recent data sets for network intrusion detection.
- Machine Learning-Based Methodologies for Cyber-Attacks and Network ... — Therefore, several machine learning-based intrusion detection system (IDS) tools have been developed to detect intrusions and suspicious activity to and from a host (HIDS—Host IDS) or, in general, within the traffic of a network (NIDS—Network IDS).
- Comparative Evaluation of Machine Learning Algorithms for Network ... — The detection of Intrusion is the major research problem faced in the area of information security, the objective is to scrutinize threats or intrusions to secure information in the network Intrusion detection system (IDS) is one of the key to conquer against unfamiliar intrusions where intruders continuously modify their pattern and methodologies.
- A Systematic Literature Review of Network Intrusion Detection System ... — Recently, deep learning and machine learning-based systems are mainly used as probable methodologies to effective detection of intrusions. This paper provides systematic literature review of several latest research papers by defining recent advancements and trends of DL- and ML-based methodologies.
- Modular deep learning-based network intrusion detection architecture ... — In recent years, AI has found a significant place in intrusion detection, too [3], [4]. Intrusion Detection Systems (IDS) play a crucial role in cybersecurity by continuously monitoring network traffic and system activities to identify potentially malicious or unauthorized behavior.
- Deep learning methods in network intrusion detection: A survey and an ... — In this paper, we first introduce a taxonomy of deep learning models in intrusion detection and summarize the research papers on this topic.
- Unveiling machine learning strategies and considerations in intrusion ... — It is an inventory of the most up-to-date research publications on intrusion detection, with a focus on the latest methodologies. The discussion focused on the prominent machine learning and deep learning algorithms, as well as the essential factors utilized for evaluating the outcomes.
- Deep Learning Approaches as a Key Enabler for Next-Generation Network ... — This paper investigates several machine-learning approaches to improve intrusion detection systems [1] by recognizing uncharacteristic and suspicious network traffic.
- A Survey of CNN-Based Network Intrusion Detection — Intrusion detection systems (IDS) can provide this capability by monitoring a network or systems and raising alerts when abnormal activities or policy violations are detected [3].
7.2 Open Datasets for Network Intrusion Detection
- NetFlow Datasets for Machine Learning-Based Network Intrusion Detection ... — Machine Learning (ML)-based Network Intrusion Detection Systems (NIDSs) have become a promising tool to protect networks against cyberattacks. ... Article Open access 01 April 2025. ... Ghorbani, A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference ...
- Network intrusion detection: An optimized deep learning approach using ... — The continuously increasing amount of network traffic necessitates using a modern intrusion detection system (IDS) in conjunction with Apache Spark, Hadoop, and Apache (Park et al., 2023, Aldwairi and Alansari, 2022). As a result, this work uses the Pyspark framework to create an efficient deep learning-based technique for intrusion detection ...
- An effective intrusion detection scheme for Distributed Network ... — For the practical implementation of IDM-DNP3 Scheme, DNP3 intrusion detection dataset [3], [4] was used. Eleven features were included in this DNP3 intrusion detection dataset, which was created in accordance with the methodological frameworks of Gharib et al. [21] and Dadkhah et al. [22]. Complete network configuration, traffic, labeled ...
- AI for Cybersecurity: ML-Based Techniques for Intrusion Detection ... — Besides, it can be categorized into two: Network Intrusion Detection System (NIDS) and Host-based Intrusion Detection System (HIDS). While NIDS is based on network traffic data that consists of whole interaction among devices on a network, HIDS is based on HIDS agent data collected from only host devices such as operating system logs.
- NetFlow Datasets for Machine Learning-Based Network Intrusion Detection ... — NetFlow Datasets for Machine Learning-Based Network Intrusion Detection Systems Mohanad Sarhan1(B), Siamak Layeghy1, Nour Moustafa2, and Marius Portmann1 1 University of Queensland, Brisbane, QLD 4072, Australia {m.sarhan,siamak.layeghy}@uq.net.au, [email protected] University of New South Wales, Canberra, ACT 2612, Australia [email protected] Abstract.
- Network intrusion detection system: A systematic study of machine ... — We then redefined our keyword as intrusion detection system, network anomaly detection, and signature-based network intrusion detectionwith the combination of machine learning or deep learning to obtain more relevant articles. As a result of phase-1, relevant articles based on the keywords were selected and stored as an initial list.
- Intrusion detection based on Machine Learning techniques in computer ... — The authors used two network traffic datasets (NSL-KDD and Kyoto University Benchmark Dataset 2009) to evaluate their model. ... they discuss the computational complexity of ML and DM methods and some open issues. ... M. Ferens, Network intrusion detection using machine learning, in: Proceedings of International Conference on Security ...
- Multi-layer perceptron for network intrusion detection — The Internet connection is becoming ubiquitous in embedded systems, making them potential victims of intrusion. Although gaining popularity in recent years, deep learning based intrusion detection systems tend to produce worse results than those using traditional machine learning algorithms. On the contrary, we propose an end-to-end methodology allowing a neural network to outperform ...
- Unveiling machine learning strategies and considerations in intrusion ... — 3.1 IDS concept. Dorothy E. Denning invented intrusion detection systems (IDS) in 1987 to detect network and computer attacks. IDS is a collection of approaches designed to detect suspicious, malicious, or unusual behavior that threatens the security of networks and computers (Oprea et al., 2021).Computer or network systems intruders can jeopardize data security by modifying, destroying, or ...
- (PDF) Network Intrusion Detection Systems: A Systematic Literature ... — The paper first elucidates the concept of network intrusion detection systems. Secondly, the taxonomy of hybrid deep learning techniques employed in designing NIDSs is presented.
7.3 Tools and Frameworks for Implementation
- An effective intrusion detection scheme for Distributed Network ... — For the practical implementation of IDM-DNP3 Scheme, DNP3 intrusion detection dataset [3], [4] was used. Eleven features were included in this DNP3 intrusion detection dataset, which was created in accordance with the methodological frameworks of Gharib et al. [21] and Dadkhah et al. [22]. Complete network configuration, traffic, labeled ...
- AI for Cybersecurity: ML-Based Techniques for Intrusion Detection ... — S.-N. Nguyen, V.-Q. Nguyen, J. Choi, K. Kim, Design and implementation of intrusion detection system using convolutional neural network for dos detection, in Proceedings of the 2nd International Conference on Machine Learning and Soft Computing, ser. ICMLSC '18 (Association for Computing Machinery, New York, NY, USA, 2018), pp. 34-38 [Online].
- Network intrusion detection system: A systematic study of machine ... — It employs tools like firewall, antivirus software, and intrusion detection system (IDS) to ensure the security of the network and all its associated assets within a cyberspace. 1 Among these, network-based intrusion detection system (NIDS) is the attack detection mechanism that provides the desired security by constantly monitoring the network ...
- PDF Guide to Intrusion Detection and Prevention Systems (IDPS) - NIST — the process of performing intrusion detection and attempting to stop detected possible incidents. Intrusion detection and prevention systems (IDPS) 1. are primarily focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators. In
- PDF Intrusion Detection Systems - csrc.nist.rip — severity over the past few years, intrusion detection systems have become a necessary addition to the security infrastructure of most organizations. This guidance document is intended as a primer in intrusion detection, developed for those who need to understand what security goals intrusion detection mechanisms serve, how to select and configure
- PDF Network Infrastructure Security Guide - U.S. Department of Defense — Implement a network monitoring solution to log and track inbound and outbound traffic, such as a network intrusion detection system (NIDS), a traffic inspector, or a full-packet capture device. Deploy multiple dedicated remote log servers to enable activity correlation among devices and detection of lateral movement.
- Attention based multi-agent intrusion detection systems using ... — Several techniques, tools, and software have been developed to protect network systems against such different security threats. An intrusion detection system (IDS) [7] is one such system that is pivotal in modern networks besides preventive security paradigms like access control systems, authentication systems, etc. Based on the principle of working and analysis methods, IDS can be categorized ...
- PDF Machine Learning for a Network- based Intrusion Detection System - DiVA — tect cyber security threats, Intrusion Detection Systems (IDS) can be used. An IDS monitors networks or computers in order to detect malicious activity. This thesis explores the use of Machine Learning (ML) algorithms to improve the detection rate of a Network-based IDS (NIDS) named Zeek [2]. 2.1Problem description
- FlowTransformer: A transformer framework for flow-based network ... — Despite the sequential nature of network communications, current ML-based NIDS research often overlooks sequential data (Kumar et al., 2021, Singh and Khare, 2022, Walling and Lodh, 2022), focusing instead on classifying individual network flow records in isolation.This is partly due to the challenges posed when trying to apply traditional RNNs due to their inability to be parallelised ...
- (PDF) A Framework for implementing an ML or DL model to improve ... — Intrusion detection systems (IDS) identify cyber attacks given a sample of network traffic collected from real-world computer networks. As a powerful classification tool, deep learning (DL) models ...








