A Host-based Intrusion Detection: Using Signature-based and AI-driven Anomaly Detection for Enhanced Cybersecurity*

Fazalur Rehman, Farhan Mushtaq, Hafsah Zaman · 2024

This research introduces a Hybrid Intrusion Detection System (HIDS) that merges signature-based detection, with AI-powered anomaly detection to enhance the accuracy and effectiveness of identifying cyber threats. The proposed HIDS demonstrates an ability to detect uncommon and sophisticated cyber threats with an accuracy rate of 90.37%. By combining Gradient Boosting and K-Nearest Neighbors (KNN) algorithms the system improves detection precision, speeds up response times, and expands coverage across network traffic. This comprehensive approach overcomes the limitations of traditional methods by enabling threat responses while reducing false positive rates. The study highlights the potential of integrating signature-based and AI-driven techniques to strengthen cybersecurity defences which emphasizes the benefits of this approach. When the system detects a potential threat, alerts are sent to the Security Operations Center (SOC) or Network Operations Center (NOC), with details such as nature of the threat, and the affected system. This study establishes a foundation for real-time cyber threat detection and intelligence sharing in cloud environments, with future Hybrid IDS versions operating across multiple hosts and supported by a web service for cross-platform compatibility and centralized alert system.

Read the paper · More papers on PaperTik