RRF ‐ IPS : A Real‐Time Reputation‐Based Intrusion Prevention System
Zhenghao Qian, Fengzheng Liu, Mingdong He, Bo Li, xuewu li, Chuangye Zhao, Gehua Fu, Yifan Hu · Engineering Reports · 2026
ABSTRACT With the rapid development of technologies such as cloud computing and the Internet of Things, organizations face the thorny reality that network attacks are becoming increasingly diverse, covert, and intelligent. Traditional signature‐based intrusion detection systems (IDSs) struggle to address zero‐day attacks and advanced persistent threats (APTs), often resulting in low detection rates and high false‐positive rates. To address this, this paper proposes an adaptive network intrusion detection system that integrates random forest (RF) and real‐time reputation evaluation. The system first preprocesses and normalizes the original network traffic and behavior logs, and then uses a random forest to perform preliminary multi‐category classification. It then introduces a historical behavior risk metric, weighting the error rate of the current detection with the device's historical risk profile using exponential decay. A comprehensive reputation score is generated using a continuously differentiable “four‐stage” smoothing function: sigmoid in the low‐confidence zone, cosine in the medium‐low zone, inverse sigmoid in the medium‐high zone, and exponential decay in the extremely high zone. Finally, RRF‐IPS's reputation scoring system executes automated policies such as bandwidth throttling, warning notifications, and session isolation or blocking, forming a closed “detect‐assess‐respond‐archive” loop. Experimental results demonstrate that, on CICIDS2017, our system improves accuracy by 0.6% and F1 score by 5.9% compared to state‐of‐the‐art methods.