Intrusion detection is the process of monitoring network traffic or system activity to identify unauthorized access, policy violations, or malicious behavior. Intrusion detection systems are generally classified as signature-based, which match activity against known attack patterns, or anomaly-based, which flag deviations from an established baseline of normal behavior and can therefore detect previously unseen attacks. Deployment architectures include network-based systems that inspect traffic at chokepoints and host-based systems that monitor activity on individual machines, often combined in layered defense strategies. Recent research combining machine learning with IoT network traffic has reported detection accuracy above 99 percent on benchmark datasets such as IoTID20, alongside a broader shift toward deep learning architectures, including transformers, for more effective pattern recognition. Other active areas include federated learning approaches and detecting intrusions in encrypted traffic and industrial control systems. As an open-access intrusion detection journal, IJACSA publishes research evaluating intrusion detection models against benchmark datasets, alongside applied detection systems for specific network environments.
Published in International Journal of Advanced Computer Science and Applications (IJACSA)
· list last refreshed October 2026
Cloud computing provides scalable infrastructure but introduces critical challenges to data privacy, trust management, and intrusion detection. To address these issues, we present a trust-aware framework that integrates…
Intrusion detection in web traffic remains a challenging task due to the high dimensionality, heterogeneity, and imbalance of normal and malicious requests. This study investigates a hybrid anomaly detection framework co…
With the widespread adoption of the Internet of Medical Things (IoMT), hospitals have become prime targets for cyberattacks. To overcome the limitations of traditional defenses and computationally heavy deep learning mod…
The explosive growth of online education platforms has led to increased exposure to cybersecurity threats, which makes secure Learning Management Systems (LMS) a critical requirement. However, the current methods often c…
New and unknown attack patterns are creating more cybersecurity issues for cloud environments. Intrusion detection systems (IDS) are usually capable of high-performance in closed-world scenarios and are less effective in…
The growing amount of heterogeneous devices with scarce resources is compromising the security of the Internet of Things (IoT), as they are more likely to adapt to a fixed and identity-based access control. Conventional…
This research provides a comprehensive synthesis of Multimodal Machine Learning (MML) as a transformative paradigm for IoT defense. By integrating heterogeneous data streams, including network flow statistics, device-lev…
This study presents an investigation of the HiTar-2024 dataset performed in terms of the distribution of label attack types and the distribution of attacks by protocol, normal, and Denial of Service (DoS) connections ove…
Ransomware is one of the most dangerous cyber threats today, as it can disrupt systems and cause serious financial losses. Traditional detection methods often fail to catch newer attacks because they can hide within norm…
Early detection of cyberattacks remains a major challenge in enterprise networks due to encrypted traffic, protocol diversity, and highly dynamic service behavior. This study evaluates a machine learning-based intrusion…