International Journal of Computer Networks & Communications (IJCNC)

AIRCC PUBLISHING CORPORATION

IJCNC 08

A NOVEL MACHINE LEARNING TECHNIQUE FOR CYBERSECURITY NETWORK INTRUSION DETECTION SYSTEM

Moulay Ibrahim El-Khalil Ghembaza
Department of Computer Science, College of Engineering and Information Technology, Onaizah Colleges, Qassim, 56447, Saudi Arabia

ABSTRACT

Network intrusion is the unauthorized access, manipulation, or interruption of computer networks and systems. It comprises a variation of illegal behaviors, such as hacking, virus deployment and data theft. Detecting and blocking intrusions is vital for protecting sensitive data and credentials to ensure the integrity and safety of digital infrastructure. To develop a Machine Learning technique for a cybersecurity Network Intrusion Detection System, this research proposes a novel Cheetah Optimization-driven Intelligent Adaptive Boosting (CO-IAB) technique to protect systems and ensure data identification against threats and breaches by detecting and responding to unauthorized or illegitimate access to computer networks. Initially, the research obtained a dataset that contains a wide range of network intrusion techniques for training the suggested detection model. The collected raw data is pre-processed using Zscore Normalization to improve the quality of the data obtained. The Kernel Principal Component Analysis
(Kernal-PCA) algorithm is employed to extract significant features from the processed data. The CO is used to optimize hyperparameters and feature selection for the subsequent IAB network architecture, improving its performance in network intrusions detection by purposely developed Python code. The analysis of the findings is evaluated with metrics parameters such as Recall, Precision, Accuracy and F1- score. The results are cross validated to authenticate the contribution of the proposed prediction model. Experimental findings show that the recommended prediction model has outperformed conventional approaches in IDS to secure network data

KEYWORDS

Cybersecurity, Network Intrusion Detection System (NIDS), Machine Learning (ML), Cheetah Optimization-Driven Intelligent Adaptive Boosting (CO-IAB).

1. INTRODUCTION

The modern era of rapid technological advancements has forced all enterprise bodies to implement Information and Communication Technology (ICT) integration. Considering that each action is now managed by the system, the business is susceptible to attacks in the case that the security of the ICT system is compromised [1, 2]. Consequently, this necessitates the use of multi-layered detection and defense mechanisms that are both capable of handling innovative system threats and able to independently adjust to new data. Such ICT systems can be secured against vulnerabilities using several approaches, such as IDSs and anomaly detection [3, 4]. The challenge of formulating rules is the limitation of anomaly-detection systems. Every technique
that is examined must be developed as well as implemented and its correctness verified. A risk linked to anomaly detection is the inability to recognize risky behavior that is consistent with a regular used patterns [5, 6]. IDS acquires a significant quantity of harmful attack data ahead of time and verifies that it contains intrusion information to build an effective defense against fresh ransomware attacks by contrasting to sample features of the system’s database [7]. Therefore, the function is to detect threats, and thus it is placed outside the capacity of the network as well as the actual channel that is used for sending and receiving data in real time. The solutions are to reduce the requirement for human involvement by using Test Access Point (TAP) or Switched Port Analyzer (SPA) to evaluate a copy of the traffic stream and utilize a previously trained algorithm to forecast the attack [8]. The discipline of cybersecurity has evolved to rely deeply on Machine Learning (ML) algorithms due to their exceptional performance and versatility in solving problems. Deep learning (DL) networks have become more dependable for unstructured tasks because they replicate the operations of humans’ brain [9, 10]. These networks use basic building blocks to handle high-level issues and produce complicated hierarchical representations. DL approaches are used to a wide collection of cybersecurity applications, including the discovery to control cyber threats. The use of DL techniques for AI and unstructured problems is becoming increasingly reliable [11]. This research aims to is to create a novel ML method for IDS applications. To protect systems and data identification related threats and breaches by detecting and responding to unauthorized or illegitimate activity in computer networks. The Cheetah Optimization-driven Intelligent Adaptive Boosting (CO-IAB) method is proposed for deriving the related results.

1.1. Research Contributions

  • The research has utilized a diverse network intrusion dataset to develop a detection model.
  • The study has employed Z-score normalization for data preprocessing and the Kernel Principal Component Analysis Kernel-PCA) technique for feature extraction.
  • The proposed CO-IAB method combines optimization techniques with boosting algorithms specifically customized for networks to protect systems and data identified attacks and breaches by detecting and respond to unauthorized activity in computer networks.
  • The study includes a comprehensive analysis of the detection model’s performance, evaluating metrics such as Recall, Precision, Accuracy and F1-score.

1.2. Motivation

Low detection accuracy, scalability and sophisticated data pre-treatment are a few of the difficulties that cybersecurity Network Intrusion Detection System (NIDS) encounter. It is frequently difficult to identify and stop threats with traditional methods due to their high false positive and false negative result rates. Large quantities of network traffic and a variety of attack vectors are difficult for these systems to handle in dynamic setting infrastructures. Existing methodologies lack empirical validation which makes it more difficult to evaluate their dependability and efficacy to real-world scenarios. Innovative technologies that increase detection accuracy, scalability, simplify data preparation and offer strong empirical validations that are thus desperately needed.

The remaining study is divided into the following sections: The literature review is presented in Section 2; the methodology is described in Section 3. Section 4 presents the comparative analysis and discusses the results; and Section 5 draws the conclusion.

2. LITERATURE REVIEW

Network and computer technologies have undergone recent developments that have led to the production of enormous amounts of credential data, raising privacy concerns. ML and DL approaches have been recently reported for NIDS, showing an exceptional level of accuracy in detecting fraudulent attacks [12, 13]. Several hybrid approaches have been proposed combining supervised learning such as Support Vector Machine (SVM), Random Forest (RF), Decision Tree (DT), and K-Nearest Neighbor (KNN); and unsupervised learning such as K-Means, Autoencoders, and DBSCAN as presented in [12]. A Nonsymmetric Deep Autoencoder (NDAE) for unsupervised feature learning with SVM on KDD Cup’99 dataset has been presented in [13]. A hybrid identification approach using Convolutional Recurrent Neural Networks (CRNNs) and DL to predict and detect cyberattacks in networks. Recurrent Neural Networks (RNNs) collect temporal characteristics, while Convolutional Neural Networks (CNNs) perform function to capture local information for prediction of the IDS system in the hybrid CRNN-based NIDS System (HCRNNIDS) [14]. The authors in [15] have defined the term IDS as a range of ML strategies, including an ensemble-based approach, RF, Gradient Boosting (GB), and other techniques. Following exhaustive applications, this technique performs better than the current approaches, showing high accuracy and low false positive rates, enhancing network and computer system integrity. To strengthen internet security, an innovative Deep Convolutional Neural Network-based intelligent detection system called DCNN has been presented in [16].

A Hybrid DL approach combining both CNN and Gated Recurrent Unit (CNN-GRU) with feature optimization using Pearson Correlation Coefficient on CICIDS-2017 dataset has been presented in [17]. The GRU in this technique addresses long-term dependency issues of CNN. However, the system fails to detect Heartbleed and XSS attacks. Grey Wolf Optimization-based SVM (GWO-SVM) has been explained in [18] for ML-based IDS to identify anomalous activities in Internet of Medical Things (IoMT). The characteristics supplied into SVM have a major impact on detection accuracy. The learning process is choosing a crucial and challenging issue in identifying the distinguishing features of traffic on networks. IDS, with an emphasis on hybrid optimization and DL is to handle these issues from pre-processed datasets in urban areas which are made possible by IoT to provide trustworthiness. IoT-provided IDS to solve these problems in metropolitan areas and MinK-means Algorithm [19].

One-Class Support Vector Machine (OCSVM) [20] has been used to train each subsystem. A unique approach to anomaly detection that makes use of ANNs [21] has been improved with the cuckoo search algorithm. Tests have been conducted using 30 percent of the NSL-KDD database, while 70 percent of the dataset has been used for training. An Intrusion Detection Hyperparameter Control System (IDHCS) as a Deep Neural Network (DNN) training and governing model for reinforcement methods. The authors in [22] have proposed a module for kmeans clustering and feature extraction. Utilizing k-means clustering as its basis, the DNN feature extractor is managed via the IDHCS to extract the most important characteristics from the network’s surroundings to detect intrusion.

The authors in [23] have evaluated many approaches for building an NIDS. The best features in the dataset have been selected by evaluating the strength of the features’ correlation with each other. In addition, the special features and performance of the AdaBoost-based technique have been presented for NIDS. The authors in [24] have tested and compared 10 ML classifiers, namely, KNN, RF, DT, GB, Logistic Regression (LR), Multinomial Naive Bayesian (MNB), Gaussian Naive Bayesian (GNB), Bernoulli Naive Bayesian (BNB), Adaptive Boosting (AdaBoost), and Multilayer Perceptron (MLP) on the UNSW-NB15 dataset. The evaluation results show that RF classifier outperforms all other classifiers with highest accuracy, precision, and F-measure. However, the effectiveness is limited to UNSW-NB15 characteristics and may not be generalized to other datasets. Authors in [25] have been implemented, tested, and compared 6 IDSs based on KNN, RF, DT, LR, Stochastic Gradient Descent (SGD), and Naive
Bayes (NB). The KNN and LR achieve almost 99% accuracy in classifying four malware variants (UART killer, I2C killer, Power Hungry, PIT-off).

Hybridized feature selection with rule evaluation and DL called DeepShield has been presented in [26]. Another hybrid IDS approach combining the Honey Badger Optimization algorithm and an Artificial Neural Network (HBO-ANN) has been presented in [27] to demonstrate the effectiveness of a DL approach. These hybrid systems improve the detection of both known and unknown intrusions, reducing risks and enhancing the security of IoT and enterprise networks. Although dimensionality reduction through biology-inspired optimization is effective, the ANN approach requires fine-tuning of the structure; and the hybrid approach increases the complexity of the model.

Existing intrusion detection approaches mainly rely on static machine learning classifiers with limited adaptability to evolving threats [28], while optimization-enhanced methods such as Enhanced Particle Swarm Optimization (EPSO)-tuned Decision Trees [29] and transfer learning with Squeeze-and-Excitation Network (SENet) and Adaptive Partial Reinforcement Optimizer (APRO) [30] demonstrate superior accuracy but suffer from premature convergence and computational overhead, respectively. The proposed Cheetah Optimization-driven Intelligent Adaptive Boosting (CO-IAB) addresses these limitations by integrating rapid metaheuristic convergence with nonlinear feature extraction and ensemble robustness for scalable, real-time intrusion detection. Table 1 summarizes and compares contemporary research studies.

Table 1 Literature Review Comparison.

A network-driven IDS is used when the target site is a network of computers or a distributed environment. IDSs are generally categorized based on their attack detection method into signature-based detection and anomaly-based detection approaches. Signature-based IDSs detect malicious activities by comparing incoming network traffic with predefined attack signatures stored in a database, enabling efficient identification of known threats with low computational complexity. However, their effectiveness is limited against zero-day attacks and previously unseen intrusion techniques. In contrast, anomaly-based IDSs analyze network and system behavior to identify deviations from established normal activity patterns, making them more suitable for detecting unknown and evolving cyber threats. To improve detection performance, anomaly-based systems increasingly employ artificial intelligence techniques, including ML algorithms such as NB, DT, RF, SVM, and KNN, as well as DL such as ANN, RNN, CNN, DNN, LSTM, and Autoencoders. These techniques enhance the system’s ability to learn complex behavioral patterns, adapt to dynamic network environments, and accurately identify both known and unknown attacks. Figure 1 shows the Operational Workflow of AI-Driven NIDS that integrates anomaly-based detection and signature-based detection mechanisms to improve cybersecurity monitoring and threat detection accuracy.

Figure 1: Operational Workflow of AI-Driven NIDS.

The system continuously analyzes network traffic, system logs, and host-level activity through two parallel processing pipelines. In the signature-based detection module, incoming data are compared to a database of known attack signatures to rapidly identify previously documented threats. Simultaneously, the anomaly-based detection module evaluates observed activities against normal behavioral profiles using ML and DL models, such as SVM, KNN, DT, NB, RNN, CNN, and DNN models. The learned behavioral patterns are stored and continuously updated within a behavior database to refine detection capabilities over time. Outputs from both detection pipelines are integrated into a centralized decision-making module that classifies activities as either malicious or benign. Malicious activities trigger alarm and response mechanisms, while normal traffic continues to be monitored. In addition, a feedback mechanism updates the baseline behavioral profiles using normal traffic classifications, thereby reducing false positives and improving the adaptability, accuracy, and resilience of IDS in dynamic network environments.

3. METHODOLOGY

The study proposes a CO-IAB approach for cybersecurity NIDS using advanced models and algorithms to identify and prevent malicious activities in computer networks. This strategy improves network security, ensures data integrity and enables proactive measures against cyberattacks by analyzing large data volumes. Figure 2 shows the overall architecture of the proposed method.

Figure 2: Architecture of the Proposed Method.

3.1. Data Collection

The dataset used in this study was obtained from Kaggle (https://www.kaggle.com/datasets/ sampadab17/network-intrusion-detection). The dataset contains both normal and malicious network traffic records collected for intrusion detection research. Each network connection is labeled according to its corresponding attack category, enabling supervised machine learning during the training process. The dataset includes multiple features extracted from Transmission Control Protocol (TCP) connections, which are used to transfer data between source and destination IP addresses using predetermined protocols. These are commonly used as indicators in NIDSs. These features describe various characteristics of network behavior and are utilized to train and evaluate the proposed model.

3.2. Data Preprocessing using Z-score Normalization

This method is the most widely used normalization technique, which standardizes all input values by transforming them to a single scale with a mean of 0 and a standard deviation (std) of 1. The mean and standard deviation are calculated and normalized as shown in Equation (1).

where x represents the original feature value, mean(X) represents the average of the feature, and std(X) represents the standard deviation. This preprocessing technique reduces the influence of varying feature magnitudes and enhances the performance of ML algorithms. Z-score normalization also helps minimize the impact of outliers within the dataset.

3.3. Feature Extraction using Kernel Principal Component Analysis (Kernel-PCA)

Kernel-PCA is used to extract nonlinear features and reduce dimensionality. Unlike traditional PCA, Kernel-PCA transforms the original input data into a higher-dimensional feature space using a nonlinear mapping function, enabling the extraction of nonlinear patterns from network traffic data. The nonlinear mapping is represented by Equation (2), where 𝜑 maps the input space
𝑅 𝑁𝑀 into a high-dimensional feature space 𝐸.

where 𝑁 represents the feature dimension, and 𝑀 the number of samples.

Instead of explicitly computing the mapping, Kernel-PCA utilizes a kernel function to calculate the inner products in the transformed feature space. The kernel function is defined in Equation (3).

{𝜑(𝑤𝑖)},𝑖 = 1,2, . . , 𝑚 indicates the mapped input vectors 𝑤𝑖 included in the feature space. Preprocessing is performed to ensure that the transformed feature vectors satisfy the zero-mean condition or 1/𝑚 ∑ 𝜑(𝑤𝑖)𝑚𝑖=1 = 0.

The kernel matrix K is constructed using the kernel function defined in Equation (3) as shown in Equation (4).

The covariance matrix of the transformed data is then computed, and the corresponding Eigenvalue problem is solved to determine the principal components. The extracted components are obtained by projecting the input data onto the Eigenvectors associated with the largest Eigenvalues. The covariance matrix in the feature space 𝐸 is given in Equation (5).

Currently, the Eigenvalue problem is solved by determining the Eigenvalues 𝜆 and Eigenvectors 𝑢 that satisfy Equation (6).

where 𝜆 is an Eigenvalue of 𝐶 and 𝑢 is the associated Eigenvector. Since the Eigenvectors lie in the span of the mapped samples, 𝑢 can be represented as a linear combination of the transformed vectors, as given in Equation (7).

where 𝛼 represents the Eigenvector coefficient vector. Substituting this representation into Equation (6) and applying the kernel function defined in Equation (3) yields the kernel Eigenvalue problem given in Equation (8).

Here, 𝜆 denotes an Eigenvalue of the kernel matrix 𝐾, while 𝛼 represents the corresponding Eigenvector coefficients. The principal components are obtained by projecting the transformed samples onto the matrix of Eigenvectors 𝑈 = [𝑢1, 𝑢2, … , 𝑢𝑚] in the feature space 𝐸. For a test sample 𝑤, the projection onto the 𝑟 𝑡ℎ principal component is computed using Equation (9).

To calculate the main components, the processes are performed as follows: first, calculate the kernel matrix K; second, compute its Eigenvectors and normalize them in 𝐸; and third, compute the test point projections onto the Eigenvectors.

In this study, polynomial and Gaussian kernels are used. The polynomial kernel is defined in Equation (10).

where 𝑑 denotes the polynomial degree.

The Gaussian kernel, known as the radial basis kernel, is defined by Equation (11).

where 𝜎2 represents the kernel width parameter.

3.4. Cheetah Optimization-driven Intelligent Adaptive Boosting (CO-IAB)

The proposed Cheetah Optimization-Driven Intelligent Adaptive Boosting (CO-IAB) model integrates the Cheetah Optimization (CO) algorithm with Intelligent Adaptive Boosting (IAB) to improve intrusion detection accuracy and reduce false positive results rates in NIDSs. The CO algorithm is used to optimize the feature selection and classifier parameters, while the IAB classifier enhances detection capability through adaptive ensemble learning.

3.4.1. Cheetah Optimization (CO)

Searching: During the exploration phase, candidate solutions are explored within the solution space. Similar to cheetah hunting behavior, candidate solutions may either remain stationary or move dynamically during the search process. Let 𝑚 denotes the cheetah population size and 𝑑 denotes the optimization problem dimension. The current position of the 𝑖𝑡ℎ cheetah in the 𝑗𝑡ℎ dimension at iteration 𝑡 is represented by 𝑜𝑖,𝑗𝑡, where 𝑖 = 1, 2, 3, … , 𝑚 and 𝑗 = 1, 2, 3, … , 𝑑. Due to this, different search strategies can be mathematically modelled. Each candidate solution corresponds to a potential optimal solution within the search space. Different search strategies can therefore be mathematically modeled to simulate the exploration behavior of cheetahs during
optimization. The position of the 𝑖𝑡ℎ cheetah is updated using Equation (12).

where the cheetah’s current and future positions within the population are represented by the symbols 𝑜𝑖,𝑗𝑡, and 𝑜𝑖,𝑗𝑡+1, respectively. Although 𝑡 indicates the maximum amount of time spent in the search process, it also indicates the search iteration. The symbols 𝛿𝑖,𝑗 stand for uniformly distributed random numbers. CO takes steady, measured steps when searching for the target solution. It is often set as 𝑡𝑇 × 0.001 and it is larger than zero. When the search process identifies promising regions, a cheetah will quickly change course. To demonstrate this behavior, multiple cheetahs at different times of the search process are assigned 𝑞̂𝑖,𝑗−1. In every cheetah population, the distance between 𝑖𝑡ℎ cheetah and a randomly selected cheetah is multiplied to produce 𝛿 𝑖,𝑗. There is always going to be one cheetah that is closer to the optimal solution. The candidate solution with the best fitness value is considered the leading solution, which is considered to be the best candidate solution.

Sitting and Waiting: During exploitation, candidate solutions may temporarily remain unchanged to intensify the local search around promising regions. In this phase, the candidate solution position remains fixed as represented in Equation (13).

Attacking: When their target solution is closer to them, cheetahs start to attack. Each cheetah adjusts its position in a population based on both the best candidate solution and the target solution. This behavior is represented using Equation (14).

Here 𝑜𝐴,𝑗𝑡 denotes the prey and represents the current position of the target solution (optimal solution) within the population at iteration 𝑡. The cheetah’s turning factor is represented by 𝑞̂𝑖,𝑗, while its interaction factor is represented by 𝛿𝑖,j𝑡 which controls the movement of candidate solutions during the optimization process. One can calculate the turning factor 𝑞̂𝑖,𝑗 using Equation (15).

where 𝑞𝑖,𝑗 and 𝛾𝑖,𝑗 are uniformly distributed random variables used to control the turning behavior and directional movement of candidate solutions during the optimization process.

A random number 𝐺 is calculated to select between the attacking and searching techniques. First, a random number between 0 and 1 is selected as 𝑄. Using this 𝑄, Equation (16) is used to calculate 𝐺.

where 𝐺 denotes the adaptive control parameter used to switch between exploration (searching) and exploitation (attack) strategies, 𝑓 represents a scaling factor controlling the search behavior, 𝑘 denotes the current search state coefficient, 𝑡 is the current iteration number, 𝑇 represents the maximum number of iterations, and 𝑄 is a uniformly distributed random number within the interval [0, 1]. Initially, two random numbers, 𝑞1𝑎𝑛𝑑 𝑞2, are chosen from [0, 1]. If 𝑞2 > 𝑞1, then go with the stationary search strategy. If it isn’t, another random number 𝑞3 is chosen from [0, 3]. If 𝐺 < 𝑞3, the search strategy is applied; otherwise, the attacking strategy is selected.

Abandoning the target solution: If the current search iteration does not improve the objective function, the candidate solution is repositioned within the search space to enhance exploration and avoid premature convergence.

3.4.2. Intelligent Adaptive Boosting (IAB)

The Intelligent AdaBoost algorithm is a commonly used ensemble learning method that iteratively builds weak classifiers using weighted training samples. The algorithm adjusts the training data distribution by focusing on underperforming samples from the previous stage and predicting performance for the next round. A detailed explanation of the implementation process and mathematical background is provided. At each iteration, the weak classifier 𝑘𝑚 that minimizes the weighted classification error is selected from the pool of candidate classifiers, as defined in Equation (17).

where 𝑙𝑡 (𝑤𝑖) is the prediction of the weak classifier for the sample 𝑤𝑖, and 𝜔𝑖(𝑡) is the weight of the sample 𝑖 at the iteration 𝑡.

Establish the classifier’s weight 𝛼𝑡 as given in Equation (18).

And 𝑓𝑡 is calculated as shown in Equation (19).

where 𝑋𝑓 is the number of misclassified samples, and 𝑋 is the total number of samples.

The sample weights are updated for the next iteration using Equations (20) and (21) based on whether the prediction of the weak classifier 𝑙𝑡 (𝑤𝑖) correctly classifies or misclassifies the training sample.

A few observations are pertinent to this AdaBoost pseudocode implementation. A family of classifiers, each of which is trained to minimize the error function, is given the current weights, which can replace the pool of classifiers used in step 1. Stated differently, it is not necessary to supply the pool of classifiers beforehand, and it only needs to exist optimally. If a restricted set of classifiers is indeed accessible, then it only needs to test the classifiers once for each data point. The scouting matrix 𝑇 can be used again in each iteration. For each classifier in the pool, the research found by multiplying 𝑇 by the transposed vector of weights 𝜔𝑖(𝑡). Rewriting the weight update step in terms of the weights allows a weight change to occur only in the misclassification. The weight vector 𝜔(𝑡)is constructed using an iterative process. With complete recalculation of each iteration, the iterative construction method is more user-friendly and productive. It is important to remember that a classifier with a weight of zero is one for which 𝑓𝑡 = 1/2 and does not outperform chance. A classifier achieving zero classification error (𝑓𝑡 = 0) would theoretically receive an infinitely large weight. The weight of a completely misclassifying classifier (𝑓𝑡 = 1) would be infinitely negative. There are several benefits of using CO-IAB for cybersecurity NIDS. It starts with the Cheetah Optimization algorithm, a bio-inspired engine that improves exploration (searching) and exploitation (attack) during optimization, thereby enhancing intrusion detection performance on networks. This method has two benefits, reducing false positives and improving detection accuracy which are essential for quickly resolving threats.

Furthermore, by dynamically adjusting the weights of weak classifiers, CO-IAB incorporates IAB and strengthens the architecture’s resistance to evolving cyber threats. Due to its adaptability, CO-IAB provides better detection performance, making it a competitive substitute for strengthening security safeguards.

Figure 3 shows the flow of the suggested CO-IAB.

Figure 3: Flowchart of CO-IAB.

4. RESULT

The proposed model has been implemented using an HP laptop with a 2.5 GHz Intel(R) Core(TM) i5-8250U CPU and 60 GB of RAM for cybersecurity NIDS. In this investigation, a comparison evaluation of the suggested method CO-IAB, has been carried out, comparing with the existing methods including DT [25], NB [25], RF [25], and Deep Shield [26], evaluating the performance metrics for Accuracy, Recall, F1-score, and Precision as given in Table 2.

Table 2: Performance Metrics.

4.1. Accuracy

In cybersecurity, the term accuracy refers to a system’s capacity to identify and classify hostile activity or threats with the fewest possible false positives and negatives. This important test shows how well an IDS sees possible threats and responds appropriately to protect the security and integrity of network systems. The suggested approach, CO-IAB has produced better results than the existing methods, as shown in Figure 4. For instance, while DT achieved an accuracy of 80%, NB achieved 98%, RF reached 97%, Deep Shield 98.1% and CO-IAB outperformed all of them with an impressive accuracy rate of 99.4%.

Figure 4: Graphical Outcome of Accuracy.

4.2. Precision.

Precision in security networks refers to the ability to consistently distinguish genuine intrusions from among the events that have been reported, particularly in intrusion detection. To reduce false positives, it calculates the percentage of accurately recognized intrusions to all occurrences labelled as intrusions. High accuracy lowers the chance of ignoring real security risks in a network by ensuring constant threat detection. The precision’s numerical and graphical results are shown in Figure 5. The suggested approach, CO-IAB has demonstrated higher precision values (98.3%) compared to other existing methods such as DT (69%), RF (97%), Deep Shield (96.8%) and NB (98%). This comparison illustrates the enhanced precise performance of the proposed approach.

Figure 5: Graphical Outcomes of Precision.

4.3. Recall

Recall refers to the system’s ability to find and review historical data on security incidents or uncertain behavior in the context of security NIDS. It involves examining stored data regarding prior events, warnings, and patterns to enhance threat detection and response capabilities as well as help to identify and mitigate potential security breaches. Figure 6 shows the recall’s numerical findings. Higher findings have been obtained when comparing the specificity values of the proposed method, CO-IAB (98.8%), with those of other previously employed techniques, such as DT (80%), RF (97%), Deep Shield (97.6%), and NB (98%).

Figure 6: Graphical Outcomes of Recall.

4.4. F1-score

The F1-score of the intrusion detection in network security quantifies the recall-to-accuracy ratio. It is essential to assess how well intrusion detection systems work. This investigation has included a comparison analysis, yielding a thorough evaluation of a system’s ability to accurately identify and categorize intrusions. Figure 7 demonstrates that the F1-score values of the suggested CO-IAB (99.2%), have been higher than those of other existing methods, such as DT (73%), RF (97%), Deep Shield (98.1%), and NB (98%).

Figure 7: Graphical Outcomes of F1-score.

A combination of their straightforwardness and readability, DT [25] is frequently used in cybersecurity. However, when dealing with complex datasets, they can have issues such as improper scaling or overfitting. The shortcomings as it can handle massive volumes of information and less susceptible to overfit. Utilizing RF [25] for interpretation and training requires more resources, which might be computationally expensive. When compared to separate decision trees, RF exhibits less transparency. Nevertheless, if complex datasets are utilized or if scaling is done wrong, they may overfit. NB [25], which can handle massive quantities of data, is less prone to excessive fitting which mitigates this drawback. Because it requires more resources, interpretation and training can result in higher calculation costs. CO-IAB reduces dimensions and increases efficacy to improve IDS. It can recognize network traffic characteristics and modify ML models such as random forests, or neural networks to enhance generalization and dependability.

5. CONCLUSION

The practical approach for strengthening digital defenses is the use of the ground-breaking COIAB technique for security detection of internet threats. By taking benefits advantage of data structures and analytics, this technique improves the system’s resilience by enabling real-time detection and management. These techniques present a preventive approach to security since theyare able to continually learn and adapt to counter new and emerging cyber threats. Additionally, the efficacy and precision of these techniques aid by reducing false positives and improving the overall network security. In modern digital era, making use of these advancements is a proactive step to safeguard critical infrastructure against attacks. The proposed approach performs better than the existing approaches in terms of Accuracy (99.4%), Precision (98.3%), Recall (98.8%), and F1-score (99.2%). CO-IAB is a powerful technique for digital safety network attack identification; however, like every tool, it has limitations. A disadvantage is the intricacy of the installation and the need for expertise in both optimization and cybersecurity methods. Because of this, business ventures without specialized staff may find it challenging to employ CO-IAB efficiently. CO-IAB’s real-time threat detection capabilities can be enhanced to handle large-scale network infrastructures, ensuring protection for cloud-based networks and enterprise-level systems as networks are expanding in both size and complexity.

CONFLICTS OF INTEREST

The author declares no conflict of interest.

REFERENCES

[1] B. Kolukisa, B.K. Dedeturk, H. Hacilar, and V.C. Gungor, “An efficient network intrusion detection approach based on logistic regression model and parallel artificial bee colony algorithm,” Computer Standards & Interfaces, vol. 89, p.103808, 2024. DOI: https://doi.org/10.1016/j.csi.2023.103808

[2] Y.A. Abid, J. Wu, G. Xu, S. Fu, and M. Waqas. “Multilevel deep neural network approach for enhanced distributed denial-of-service attack detection and classification in software-defined Internet of Things networks.” IEEE Internet of Things Journal, vol. 11, no. 14, pp.24715-24725, 2024. DOI: https://doi.org/10.1109/JIOT.2024.3376578

[3] Y.C. Wang, Y.C.Houng, H.X. Chen, and S.M. Tseng, “Network anomaly intrusion detection based on deep learning approach,” Sensors, vol. 23, no.4, p.2171, p.116429, 2024. DOI:https://doi.org/10.3390/s23042171

[4] S. Gupta, C. Maple, and R. Passerone, “An investigation of cyber-attacks and security mechanisms for connected and autonomous vehicles,” IEEE Access, 2023. DOI:https://doi.org/10.1109/ACCESS.2023.3307473

[5] L. Santos, R. Gonçalves, C. Rabadao, and J. Martins, “A flow-based intrusion detection framework for Internet of things networks,” Cluster Computing, pp.1-21, 2023. DOI:https://doi.org/10.1007/s10586021-03238-y

[6] S.H. Oh, J. Kim, J.H. Nah, Park, J. “Employing Deep Reinforcement Learning to Cyber-Attack Simulation for Enhancing Cybersecurity,” Electronics, vol. 13, no.3, p.555, 2024. DOI:https://doi.org/10.3390/electronics13030555

[7] V. Ciric, M. Milosevic, D. Sokolovic, I. Milentijevic, “Modular deep learning-based network intrusion detection architecture for real-world cyber-attack simulation,” Simulation Modelling Practice and Theory, p.102916, 2024. DOI:https://doi.org/10.1016/j.simpat.2024.102916

[8] C. Zhang, D. Jia, L. Wang, W. Wang, F. Liu, A. Yang, “Comparative research on network intrusion detection methods based on machine learning,” Computers & Security, vol. 121, p.102861, 2022. DOI:https://doi.org/10.1016/j.cose.2022.102861

[9] S. Roy, J. Li, B. J. Choi, & Y. Bai, “A lightweight supervised intrusion detection mechanism for IoT networks,” Future Generation Computer Systems, vol. 127, pp.276-285, 2022. DOI:https://doi.org/10.1016/j.future.2021.09.027

[10] H. Attou, A. Guezzaz, S. Benkirane, M. Azrour, Y. Farhaoui, “Cloud-based intrusion detection approach using machine learning techniques,” Big Data Mining and Analytics, vol. 6, no.3, pp.311-320, 2023. DOI:https://doi.org/10.26599/BDMA.2022.9020038

[11] B.A. Alabsi, M. Anbar, S.D.A. Rihan, “Conditional tabular generative adversarial based intrusion detection system for detecting DDoS and DoS attacks on the internet of things networks,” Sensors, vol. 23, no.12, p.5644, 2023. DOI:https://doi.org/10.3390/s23125644

[12] Navaneetha, Vangara, Prathi Bhargavi, Rayapalli Chandu, Vadi Bhavani, D. Bhagyaraj Yadav, and Prasad Dharnasi. “Machine learning based intrusion detection system using supervised and unsupervised learning.” International Journal of Engineering & Extended Technologies Research (IJEETR), vol. 8, no. 2, p.505-511, 2026. DOI:https://doi.org/10.15662/IJEETR.2026.0802004

[13] E.-U.-H. Qazi, M. Imran, N. Haider, M. Shoaib, and I. Razzak, “An intelligent and efficient network intrusion detection system using deep learning,” Computers and Electrical Engineering, vol. 99, p.107764, 2022. DOI:https://doi.org/10.1016/j.compeleceng.2022.107764

[14] M.A Hossain, and M.S. Islam, “Ensuring network security with a robust intrusion detection system using ensemble-based machine learning,” Array, vol. 19, p.100306, 2023. DOI:https://doi.org/10.1016/j.array.2023.100306

[15] E.U.H. Qazi, M.H. Faheem, and T. Zia, “HDLNIDS: hybrid deep-learning-based network intrusion detection system,” Applied Sciences, vol. 13, no. 8, p.4921, 2023. DOI:https://doi.org/10.3390/app13084921

[16] Shebl, A., Elsedimy, E.I., Ismail, A., Salama, A.A. and Herajy, M., “DCNN: A Novel Binary and Multi-Class Network Intrusion Detection Model via Deep Convolutional Neural Network,” EURASIP Journal on Information Security, no. 1, p.36, 2024. DOI:https://doi.org/10.21203/rs.3.rs-4171645/v1

[17] Henry, S. Gautam, S. Khanna, K. Rabie, T. Shongwe, P. Bhattacharya, B. Sharma, and S. Chowdhury, “Composition of hybrid deep learning model and feature optimization for intrusion detection system,” Sensors, vol. 23, no, 2, p.89014, 2023. DOI:https://doi.org/10.3390/s23020890

[18] K. Ramakrishna, N. Yamsani, I.H. Mohammed, H. Mohammad, and K. Al-Attabi, “Intrusion Detection System in IoT using Grey Wolf Optimization-Based Support Vector Machine,” In 2023 International Conference on Integrated Intelligence and Communication Systems (ICIICS), pp.1-5. IEEE, November 2023. DOI:https://doi.org/10.1109/ICIICS59993.2023.10420977

[19] S.K. Gupta, M. Tripathi, J. Grover, “Hybrid optimization and deep learning-based intrusion detection system,” Computers and Electrical Engineering, vol. 100, p.107876, 2022. DOI:https://doi.org/10.1016/j.compeleceng.2022.107876

[20] H. Alazzam, A. Sharieh, K.E. Sabri, “A lightweight intelligent network intrusion detection system using OCSVM and Pigeon-inspired optimizer,” Applied Intelligence, vol. 52, no. 4, pp.3527-3544, 2022. DOI:https://doi.org/10.1007/s10489-021-02621-x

[21] M. Imran, S. Khan, H. Hlavacs, F.A. Khan, S. Anwar, “Intrusion detection in networks using cuckoo search optimization,” Soft Computing, vol. 26, no. 20, pp.10651-10663, 2022. DOI:https://doi.org/10.1007/s00500-022-06798-2

[22] Y.N. Kunang, S. Nurmaini, D. Stiawan, and B.Y. Suprapto, “Attack classification of an intrusion detection system using deep learning and hyperparameter optimization,” Journal of Information Security and Applications, vol. 58, p.102804, 2021. DOI:https://doi.org/10.1016/j.jisa.2021.102804

[23] Ahmad, Q.E. UlHaq, M. Imran, M.O. Alassafi, R.A. AlGhamdi, “An efficient network intrusion detection and classification system,” Mathematics, vol. 10, no. 3, p.530, 2022. DOI:https://doi.org/10.3390/math10030530

[24] O. Almomani, M. A. Almaiah, A. Alsaaidah, S. Smadi, A. H. Mohammad, & A. Althunibat, “Machine learning classifiers for network intrusion detection system: comparative study,” In 2021 International Conference on Information Technology (ICIT), pp. 440-445, 2021. DOI:https://doi.org/10.1109/ICIT52682.2021.9491770

[25] N.A. Kose, R. Jinad, A. Rasheed, N. Shashidhar, M. Baza, H. Alshahrani, “Detection of Malicious Threats Exploiting Clock-Gating Hardware Using Machine Learning,” Sensors, vol. 24, no. 3, p.983, 2024. DOI:https://doi.org/10.3390/s24030983

[26] H. Lin, “DeepShield: A Hybrid Deep Learning Approach for Effective Network Intrusion Detection,” International Journal of Advanced Computer Science and Applications, vol. 14, no. 7, 2023. DOI:https://doi.org/10.14569/IJACSA.2023.01407117

[27] Chinnasamy, Ramya, Malliga Subramanian, and Nandita Sengupta, “Empowering Intrusion Detection Systems: A Synergistic Hybrid Approach with Optimization and Deep Learning Techniques for Network Security,” International Arab Journal of Information Technology (IAJIT), vol. 22, no. 1, 2025. DOI:https://doi.org/10.34028/iajit/22/1/6

[28] R. Alshamy, and M. A. Akcayol, “Intrusion detection model using machine learning algorithms on NSL-KDD dataset,” International Journal of Computer Networks and Communications (IJCNC), vol.16, no. 6, 2024. DOI:https://doi.org/10.5121/ijcnc.2024.16605

[29] S. Songma, W. Netharn, and S. Lorpunmanee, “Extending network intrusion detection with enhanced particle swarm optimization techniques,” International Journal of Computer Networks and Communications (IJCNC), vol. 16, no. 4, 2024. DOI:https://doi.org/10.5121/ijcnc.2024.16404

[30] V. H. Le, H.-T. Nguyen, C. V. Trinh, and T. Minh Hieu, “Advanced intrusion detection and classification using transfer learning with squeeze-and-excitation network and adaptive optimization in big data,” International Journal of Computer Networks & Communications (IJCNC), vol 17, no. 6, 2025. DOI:https://doi.org/10.5121/ijcnc.2025.17606

Leave a comment

Information

This entry was posted on August 22, 2026 by .