This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space.
Abstract
Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space. An anti-data-leakage protocol (stratified partitioning, post-split normalization, five-fold cross-validation, and a SHA-1 cryptographic membership audit of an 8881 –flow test sub-sample) found no hash collisions between this sub-sample and the evaluation partitions. The framework added 32,670 authentic flows, increasing SQL Injection from 21 to 10,678, XSS from 652 to 13,212, and WBF from 1507 to 10,960. Among four evaluated ensemble models, LightGBM performed best, achieving 99.85% Accuracy, 99.85% F1-score, 99.29% Balanced Accuracy, and 97.87 ± 1.88% in five-fold cross-validation, improving detection rates by 44.9% (XSS), 23.0% (WBF), and 16.6% (SQL Injection) over the original dataset. A volume-matched ablation study showed comparable aggregate accuracy to synthetic balancing methods (SMOTE, SMOTE-Tomek), while geometric diversity analysis confirmed that authentic traffic occupies feature-space regions unreachable by interpolation, and chronological holdout evaluation confirmed generalization to unseen traffic (F1: 98.53–99.90%). Real-traffic enrichment thus offers a practical, more realistic complement to synthetic balancing for minority Web-attack detection.
This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.
Muhammad Azzam Anshori, R. Amri· Journal of Computer Science...· 0 citations
A flow-based detection method, making use of lightweight protocols like NetFlow and sFlow to identify SQLI attacks, which minimizes the need for computationally expensive packet inspection, which is going to render the process of detection more trustworthy and economical, particularly within high-traffic conditions.
P. Vinoth, K. Sudar, S. Muthukumar· Journal of Computer Science· 0 citations
Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important...
The development of robust, modern network threat detection models is often hindered by the limitations of existing benchmark datasets. These often suffer from traffic class imbalance, poor documentation, and pervasive mislabeling. To address the identified gaps, this article introduces the Orion 2026, a novel benchmark...
V. Schiavon, Matheus Riki Nakanishi, Gustavo Hideyuki Kitamura Nishikawa et al.· IEEE Access· 0 citations
This paper evaluates a passive Hybrid Network-based Intrusion Detection System (Hybrid-NIDS) prototype that combines Suricata with Random Forest flow classification and centralized ELK-based alert handling. The study explicitly separates benchmark evaluation from PCAP/live operational validation and controls exact feat...
Quoc-Cuong Tang, H. Huỳnh, V. Phan et al.· 0 citations
An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.
Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al.· Journal of Computer Virology...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.