Intrusion detection is the process of monitoring network traffic or system activity to identify unauthorized access, policy violations, or malicious behavior. Intrusion detection systems are generally classified as signature-based, which match activity against known attack patterns, or anomaly-based, which flag deviations from an established baseline of normal behavior and can therefore detect previously unseen attacks. Deployment architectures include network-based systems that inspect traffic at chokepoints and host-based systems that monitor activity on individual machines, often combined in layered defense strategies. Recent research combining machine learning with IoT network traffic has reported detection accuracy above 99 percent on benchmark datasets such as IoTID20, alongside a broader shift toward deep learning architectures, including transformers, for more effective pattern recognition. Other active areas include federated learning approaches and detecting intrusions in encrypted traffic and industrial control systems. As an open-access intrusion detection journal, IJACSA publishes research evaluating intrusion detection models against benchmark datasets, alongside applied detection systems for specific network environments.
Published in International Journal of Advanced Computer Science and Applications (IJACSA)
· list last refreshed October 2026
The rapid expansion of Internet of Things (IoT) deployments has increased the exposure of interconnected devices to cyber threats, particularly in heterogeneous and resource-constrained environments. Although recent rese…
A rapid increase in the instances of cyberattacks has been observed with the expanding digitization. This leads to an urgent and critical need for developing robust intrusion detection systems (IDS) which can identify th…
The rapid growth of computer networks has increased demand for more sophisticated tools for network traffic analysis and monitoring. The increasing reliance on networks has amplified the need for robust security and intr…
The increasing connectivity of systems and the rapid growth of the Internet have intensified cybersecurity threats. It has been demonstrated that conventional signature-based intrusion detection methods are deficient, es…
The Internet of Medical Things (IoMT) environment is highly sensitive due to the nature of medical data and its direct connection to patient health, making it a prime target for sophisticated cyberattacks. This study exp…
The rapid expansion of 5G enabled Vehicle to Everything (V2X) communication has evolved into an intelligent transportation system by supporting applications such as autonomous driving, real-time traffic optimization, and…
Underwater Wireless Sensor Networks (UWSNs) are commonly employed for exploring and exploiting aquatic areas, and its role is very important and more beneficial precisely in hostile and constrained marine environments. H…
Address Resolution Protocol (ARP) is a standard protocol used to map an IP address to its MAC address so the network can send packets to its destination. Office networks, which typically have limited network resources, a…
The increasing interconnectivity of smart grids exposes critical energy infrastructure to more sophisticated cyber threats, necessitating adaptable and auditable security measures. This study presents a blockchain-enable…
In the last few years, cyberattacks have become more complex, and it is becoming increasingly necessary to establish secure networks. This study examines enhancements to intrusion detection systems (IDSs) with the implem…