Skip to content
Open access

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

Sep 2026 · Information · 0 citations · 31 references

TL;DR

This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space.

Abstract

Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space. An anti-data-leakage protocol (stratified partitioning, post-split normalization, five-fold cross-validation, and a SHA-1 cryptographic membership audit of an 8881 –flow test sub-sample) found no hash collisions between this sub-sample and the evaluation partitions. The framework added 32,670 authentic flows, increasing SQL Injection from 21 to 10,678, XSS from 652 to 13,212, and WBF from 1507 to 10,960. Among four evaluated ensemble models, LightGBM performed best, achieving 99.85% Accuracy, 99.85% F1-score, 99.29% Balanced Accuracy, and 97.87 ± 1.88% in five-fold cross-validation, improving detection rates by 44.9% (XSS), 23.0% (WBF), and 16.6% (SQL Injection) over the original dataset. A volume-matched ablation study showed comparable aggregate accuracy to synthetic balancing methods (SMOTE, SMOTE-Tomek), while geometric diversity analysis confirmed that authentic traffic occupies feature-space regions unreachable by interpolation, and chronological holdout evaluation confirmed generalization to unseen traffic (F1: 98.53–99.90%). Real-traffic enrichment thus offers a practical, more realistic complement to synthetic balancing for minority Web-attack detection.

Read PDF

Similar papers

Open access Aug 2026

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Muhammad Azzam Anshori, R. Amri · 0 citations
Open access Aug 2026

Enhancing SQL Injection Detection: A Machine Learning Approach Using Network Flow Data

A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.

P. Vinoth, K. Sudar, S. Muthukumar · 0 citations
#machine learning Preprint Sep 2026

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important...

Uday Shankar Roy, Mahbuba Jahan Minu · 0 citations
Open access 2026

Orion 2026: An IP Flow Dataset for Network Traffic Analysis and DDoS Intrusion Detection

The development of robust, modern network threat detection models is often hindered by the limitations of existing benchmark datasets. These often suffer from traffic class imbalance, poor documentation, and pervasive mislabeling. To address the identified gaps, this article introduces the Orion 2026, a novel benchmark...

V. Schiavon, Matheus Riki Nakanishi, Gustavo Hideyuki Kitamura Nishikawa et al. · 0 citations
Preprint Sep 2026

Passive Hybrid Network-Based Intrusion Detection System (Hybrid-NIDS) Combining Suricata and Random Forest

This paper evaluates a passive Hybrid Network-based Intrusion Detection System (Hybrid-NIDS) prototype that combines Suricata with Random Forest flow classification and centralized ELK-based alert handling. The study explicitly separates benchmark evaluation from PCAP/live operational validation and controls exact feat...

Quoc-Cuong Tang, H. Huỳnh, V. Phan et al. · 0 citations

Real-time detection of cryptographic key misuse in software-defined networks using incremental learning

An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.

Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.