[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126358-en":3,"doc-seo-126358-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126358,962085564381,"Clementine","https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8",8,"Research & Report","A Hybrid Machine Learning Framework for Intrusion Detection - Comparative Evaluation and Statistical Validation","Increasing sophistication and frequency of cyberattacks intensify the need for intrusion detection systems that are accurate and adaptive. Traditional signature-based and anomaly-based approaches face limitations, including poor resistance to zero-day exploits and elevated false-positive rates. This paper integrates supervised, unsupervised, and deep learning methods into intrusion detection using datasets such as NSL KDD and CICIDS2017. Comparisons and statistical validation are performed, including practical integration with Snort and Zeek, showing ML-driven IDS outperforming traditional methods while highlighting challenges in dataset representativeness, computation, and deep model interpretability.","A Hybrid Machine Learning Framework for Intrusion Detection: Comparative Evaluation and Statistical Validation  \nMuhammad Rashid, Arbab Masood Ahmad, Yasir Saleem Afridi, Rehmat Ullah Department of Computer Systems Engineering, University of Engineering and Technology Peshawar  \n*Correspondence:  [m.rashid.afridi@gmail.com](m.rashid.afridi@gmail.com),  [arbabmasood@uetpeshawar.edu.pk](arbabmasood@uetpeshawar.edu.pk), [yasirsaleem@uetpeshawar.edu.pk](yasirsaleem@uetpeshawar.edu.pk), [rehmatullah@uetpeshawar.edu.pk](rehmatullah@uetpeshawar.edu.pk)  \nCitation | Rashid. M, Ahmad. A. M, Afridi. Y. S, Ullah. R,“A Hybrid Machine Learning Framework for Intrusion Detection: Comparative Evaluation and Statistical Validation”, IJIST, Vol. 07 Issue. 04 pp 2351-2364, October 2025  \nReceived| August 28, 2025 Revised| October 05, 2025 Accepted| October 07, 2025 Published| October 09, 2025.   \nThe increasing sophistication and frequency of cyberattacks have intensified the need  \nfor Intrusion Detection Systems (IDS) that are both accurate and adaptive. Traditional  \nIDS, whether signature based or anomaly based, provides foundational protection but faces well documented limitations: signature based systems struggle against zero day exploits, while anomaly based systems often produce high false positive rates. To address these challenges, researchers and practitioners are increasingly turning to Machine Learning (ML) asa means of enhancing IDS capabilities. This paper explores the integration of ML techniques supervised, unsupervised, and deep learning into IDS frameworks and evaluates their effectiveness using widely recognized datasets, including NSL KDD and CICIDS2017 . Supervised learning methods such as Random Forest and Support Vector Machines (SVM) demonstrate strong classification abilities, while unsupervised clustering approaches offer promise in identifying novel attacks. Deep learning models, particularly Recurrent Neural Networks (RNNs), show state of the art performance in capturing sequential traffic patterns and detecting subtle anomalies. In addition to model comparisons, this study emphasizes the practical relevance of ML enhanced IDS by examining its integration with established tools like Snort and Zeek. Our results highlight that ML driven IDS consistently outperforms traditional approaches, with RNNs and Random Forest achieving the highest balance of accuracy and efficiency. The findings underscore the potential of ML based IDS to serve asthe next frontier in cybersecurity, offering improved detection accuracy, reduced false alarms, and adaptability to evolving threats. At the same time, challenges remain in terms of dataset representativeness, computational demands, and the interpretability of deep learning models. By situating the analysis within both academic research and real world deployment contexts, this paper contributes to a clearer understanding of the opportunities and trade offs in advancing IDS through machine learning.  \nKeywords: Intrusion Detection System (IDS); Cybersecurity; Machine Learning (ML); Supervised Learning; Unsupervised Learning; Deep Learning  \nIntroduction:  \nThe swift growth of digital infrastructure and the widespread adoption of internet connected devices have reshaped the way societies and organizations function. Although digital transformation has unlocked vast opportunities, it has simultaneously made networks more vulnerable to increasingly sophisticated cyber threats. Cyberattacks such as ransomware, distributed denial of service (DDoS), advanced persistent threats (APTs), and zero day exploitsnow occur with alarming frequency, causing financial losses, reputational damage, and disruptions to critical services. According to industry reports [1], the global cost of cybercrime continues to escalate annually, underscoring the urgent need for advanced and reliable defense mechanisms [2] .  \nIntrusion Detection Systems (IDS) play a pivotal role in this defense ecosystem by continuously m","cbCaipjfSK8enCmX","https://ap.wps.com/l/cbCaipjfSK8enCmX","pdf",518733,9,1,14,"English","en",105,"# Introduction\n## Intrusion Detection Systems and Their Limitations\n## Machine Learning for Enhanced IDS\n## Related Research and Motivation","[{\"question\":\"What limitations do traditional signature-based and anomaly-based IDS have?\",\"answer\":\"Signature-based IDS struggles against zero-day exploits, while anomaly-based IDS often produces high false-positive rates that increase the operational burden for security teams.\"},{\"question\":\"Which machine learning approaches are integrated into the proposed IDS framework?\",\"answer\":\"The paper considers supervised learning (e.g., Random Forest, SVM), unsupervised learning (e.g., clustering), and deep learning models such as Recurrent Neural Networks (RNNs).\"},{\"question\":\"How is the practical relevance of ML-enhanced IDS assessed?\",\"answer\":\"The study examines integration with established tools like Snort and Zeek and performs model comparison with emphasis on accuracy and efficiency, reporting that ML-driven IDS can reduce false alarms and improve adaptability.\"}]","A Hybrid Machine Learning Framework for Intrusion Detection - Comparative Evaluation and Statistical Validation | PDF",1785904652,35,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"a-hybrid-machine-learning-framework-for-intrusion-detection-comparative-evaluation-and-statistical-validation","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/a-hybrid-machine-learning-framework-for-intrusion-detection-comparative-evaluation-and-statistical-validation/126358/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"What limitations do traditional signature-based and anomaly-based IDS have?","Question",{"text":77,"@type":78},"Signature-based IDS struggles against zero-day exploits, while anomaly-based IDS often produces high false-positive rates that increase the operational burden for security teams.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"Which machine learning approaches are integrated into the proposed IDS framework?",{"text":82,"@type":78},"The paper considers supervised learning (e.g., Random Forest, SVM), unsupervised learning (e.g., clustering), and deep learning models such as Recurrent Neural Networks (RNNs).",{"name":84,"@type":75,"acceptedAnswer":85},"How is the practical relevance of ML-enhanced IDS assessed?",{"text":86,"@type":78},"The study examines integration with established tools like Snort and Zeek and performs model comparison with emphasis on accuracy and efficiency, reporting that ML-driven IDS can reduce false alarms and improve adaptability.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,112,117,122,125,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":110,"slug":111},5,"Comic",60,"comic",{"id":113,"doc_module":4,"doc_module_name":47,"category_name":114,"show_sort_weight":115,"slug":116},6,"Technology",50,"technology",{"id":118,"doc_module":4,"doc_module_name":47,"category_name":119,"show_sort_weight":120,"slug":121},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":123,"slug":124},30,"research-report",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":108,"slug":139},19,"General","general"]