Advancing Intrusion Detection: A Deep Analysis of Anomalies and Network Protocol Vulnerabilities

Ali S. Rachini, Souheil Taouk, Maroun Abi Assaf, Rida Khatoun · 2025

In today’s cyber warfare landscape, the Intrusion Prevention System (IPS) plays a critical role in identifying harmful content before it escalates. However, anomaly detection techniques still struggle with high false alert rates and poor accuracy. In Security Operations Centers (SOCs), selecting the right solution often feels overwhelming, especially without access to large datasets for optimization. Our research using the NSL-KDD dataset compared several classification algorithms for detecting unusual network traffic patterns. We uncovered significant insights into how attackers exploit vulnerabilities in network protocols, equipping SOC teams with the knowledge to identify and prevent attacks effectively. Our Random Forest (RF) and XGBoost models achieved impressive accuracies of 99.33% and 99.29%, respectively, with the RF model reaching 99.86% accuracy, highlighting its potential for pattern recognition with minimal input data.

Read the paper · More papers on PaperTik