Web Attack Intrusion Detection System Using Machine Learning Approaches for Cybersecurity
Ali E. Takieldeen, Aya El-Sayed El-Metwaly, Rahma Rezk Elzahdany, Rahma Fawzy Zidan, Areej Ahmed Lotfy, Doniya Mohamed Abdelhady · 2025
This paper presents a real-time intrusion detection system (IDS) for web attacks that leverages machine learning techniques applied to web server logs. The increasing sophistication of web attacks necessitates advanced detection methods that can adapt to evolving threat landscapes. Our system addresses this challenge by employing a multi-stage approach: (1) comprehensive feature engineering, including novel features extracted from web logs, (2) feature selection to identify the most relevant attributes, (3) classification using various machine learning algorithms (Support Vector Machine, Gradient Boosted Trees, Decision Tree, and Random Forest), and (4) a real-time detection engine that processes incoming web logs. We evaluate our system on a dataset sourced from IEEE Data port (Deng et al., 2019), containing attacks such as SQL injection and cross-site scripting (XSS). Experimental results demonstrate that the Random Forest classifier achieves the highest accuracy (99.83%), precision (96.66 %), and recall (99.66 %), significantly outperforming other algorithms and a baseline model without the enhanced features. The system's integration with Telegram APIs facilitates real-time alerts and reporting. This research contributes to the field of cybersecurity by providing a robust and adaptable solution for real-time web attack detection, capable of identifying complex intrusion patterns with low false positive rates. Future work will focus on enhancing the system's ability to detect a wider range of attacks and adapting to concept drift.