DESIGN AND IMPLEMENTATION OF A MACHINE LEARNING MODEL FOR NETWORK INTRUSION DETECTION
Résumé
Abstract Network intrusion detection has become difficult because enterprise traffic is high-volume, heterogeneous and continuously altered by encryption, cloud adoption, remote access and adversarial behaviour. This study designed and implemented a supervised machine-learning model that classifies network flows as benign or intrusive while preserving operational interpretability and low false-alarm rates. The proposed architecture integrates traffic capture, flow aggregation, data cleaning, encoding, scaling, feature screening, imbalance-aware model training, thresholded inference and alert generation. Five classifiers logistic regression, decision tree, random forest, gradient boosting and linear support vector machine were compared on a reproducible 15,000-record flow-like benchmark containing 32 statistical attributes and an 82:18 benign-to-intrusion ratio. Evaluation used a stratified 75:25 split and accuracy, precision, recall, F1-score, receiver operating characteristic area under the curve and confusion-matrix analysis. Random forest produced the strongest overall balance, attaining 94.72% accuracy, 97.10% precision, 73.32% recall and an F1-score of 83.55% in the implemented benchmark, while linear models offered lower computational cost but weaker nonlinear discrimination. The findings show that preprocessing, class-aware learning and per-class metrics are as important as classifier choice. The paper contributes an implementation-ready framework, pseudocode, data schema, model-comparison evidence and deployment controls for drift, privacy and retraining. Because benchmark accuracy may overstate field performance, the proposed system requires temporal validation and monitoring before production use. The architecture is suitable for campus, small-enterprise and cloud-edge networks where explainable flow-based detection is preferred to payload inspection. Keywords: Network intrusion detection, machine learning, random forest, anomaly detection, cybersecurity, flow classification
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueAuteur(s)
Statistiques
Consultations : 1
Téléchargements : 0