AI-Powered Threat Detection and Response: Leveraging Machine Learning for Real-Time Intrusion Detection Systems (IDS) Using Network Traffic Data
Mohammed Ibrahim El-Hajj · 2025
The growing complexity of cyberattacks necessitates advanced intrusion detection systems (IDS) capable of real-time threat identification. This study proposes a hybrid machine learning (ML) framework to enhance IDS by combining static and temporal analysis of network traffic. Leveraging benchmark datasets—CICIDS2017, UNSW-NB15, and KDD Cup 1999—we developed a model integrating Random Forest (RF) for static feature interpretation and Long Short-Term Memory (LSTM) networks for sequential pattern recognition. Data preprocessing included SMOTE-ENN for class imbalance mitigation and mutual information for feature selection. Deployed on an edge-compatible pipeline using Apache Kafka and TensorRT, the framework achieved a 98.7% F1-score and 99.2% AUC-ROC on CICIDS2017, outperforming state-of-the-art models like CNNs and SVMs. Real-time testing demonstrated a latency of 4.2 ms and throughput of 12,000 requests/second, surpassing existing approaches by 60%. Case studies confirmed robust detection of DDoS, brute force, and SQL injection attacks with ¡1% false positives. This work bridges the gap between accuracy and speed in ML-based IDS, offering a scalable solution for IoT, industrial control systems, and 5G networks. Future research will focus on encrypted traffic analysis and federated learning for decentralized deployment.