Network Intrusion Detection System Using Random Forest
Mukesh Patidar, Abhijeet Dave, Daxa Vekariya, Bhavana Udumula, Kiran Kumar Porla, Bhavya Nidimamidi · 2025
Intrusion Detection Systems (IDS) are critical to secure networks against changing cyber-attacks. This study brings improvements in IDS methods, machine learning (ML) and deep learning (DL) approaches to overcome issues like low detection rates, data imbalance, and new attack types. A new model, AB-TRAP, was proposed to address conventional IDS shortcomings. AB-TRAP applies current databases and realworld deployment techniques from constructing traffic datasets to testing ML models, demonstrated high accuracy and low resource consumption in local and internet environments. To improve zero-day attack detection, the study emphasizes applying “Benford's Law” for feature selection. This method, in conjunction with semi-supervised learning algorithms such as one-class support vector machines (SVM), proved to be highly effective in detecting anomalies. The research also highlights the significance of Explainable AI (XAI) for ML-based IDS. By overcoming issues like the black-box behavior of ML models and integrating human-in-the-loop systems, XAI provides interpretability and usability to security analysts. Ensemble algorithms like Decision Tree, Random Forest, Extra Tree, and XGBoost were compared and were found to perform better than individual algorithms in terms of accuracy, recall, and F1-score. The Random Forest-based IDS achieved over 99% accuracy on NSL-KDD and UNSW-NB15, improving intrusion detection with SMOTE-clustering techniques and testing on CICIDS 2017.