AI-Assisted Custom Rule Generation for Signature-Based Network Intrusion Detection Systems
Micheal Opeyemi Durodola · International Journal of Research and Innovation in Applied Science · 2025
Signature-based Network Intrusion Detection System plays a critical role in the security infrastructure of a network domain. It function solely by using predefined rules to compare incoming network traffic against a database of attack signatures to determine if the network traffic is safe or malicious. Although, this method has proven to be effective with known attack signatures, network security expert still need to spend quality time to investigate activities in a particular network domain to create custom rules that will complement the predefined signatures. This dissertation investigates an AI-assisted approach to generate custom rules for NIDS. Leveraging machine learning to enhance adaptability, accuracy, and speed. In this study, Random Forest Classifier which is a subset of a supervised machine learning model was trained using the NSL-KDD dataset for binary classification of network traffic and provide additional insight on the network traffic if it is malicious. The Random Forest Classifier was selected due to its robustness and efficiency in handling imbalance labelled dataset that are common in network traffic data. The proposed system achieves an accuracy of 99.92% and precision of 99.90% showing its efficiency is classifying network traffic and reducing false positive. By focusing on custom rules generation, this research reveals the transformative effort go AI in developing proactive solution to organisation-specific security risks, offering a significant step forward in reinforcing the security stance of a NIDS.