[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120161-en":3,"doc-seo-120161-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120161,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Real-Time Intrusion Detection via Machine Learning Approaches","Real-time hostile-action detection is essential for safeguarding network infrastructures in cybersecurity. Intrusion Detection Systems (IDS) commonly use signature-based or anomaly detection, where anomaly approaches leverage AI to recognize previously unseen cyberattacks. This work introduces ReTiNA-IDS, integrating CICFlowmeter with machine learning to analyze real-time network traffic patterns and identify abnormal behavior suggesting intrusion. Random forest and multi-layer networks, trained using CSECICI-IDS2018, are evaluated in realistic scenarios and show effective intrusion identification.","Real-Time Intrusion Detection via Machine Learning Approaches  \nErik Murtaj1 , Fausto Marcantoni1 , Michele Loreti1 , Michela Quadrini1, * and Hans-Friedrich Witschel2  \n1 School of Science and Technology, University of Camerino, Via Madonna delle Carceri, 9, Camerino, 62032, Italy  \n2 FHNW University of Applied Sciences and Arts Northwestern Switzerland, Riggenbachstrasse 16, CH-4600 Olten  \nAbstract  \nIn many cybersecurity contexts, the real-time detections of hostile actions play a fundamental role in protecting network infrastructures. In this scenario, Intrusion Detection Systems (IDS), based on signature-based or anomaly detection, are widely used to analyze network traffic. The signature-based detection relies on databases of known attack signatures, and anomaly detection is mainly based on Artificial Intelligence (AI) techniques. The latter is promising to detect new kinds of cyberattacks in real time.  \nIn this work, we propose ReTiNA-IDS, a framework that integrates the CICFlowmeter tool with Machine Learning techniques to analyze Real-Time network traffic patterns and detect abnormalities that may suggest a possible intrusion. The considered machine learning techniques, random forest and multi-layer network, are based on selected features to enhance efficiency and scalability. To select the features and train the models, we use a version of the public dataset, CSECICI-IDS2018 . The framework’s effectiveness has been tested in real-case scenarios by identifying different forms of intrusion. Analyzing the results, we conclude that the proposed solution shows valuable features.  \nKeywords  \nRandom Forest, Feature Selection, analysis of Real-Time network traffic, Intrusion Detection Systems  \n1. Introduction  \nIntrusion Detection Systems (IDS) are relevant tools employed in cybersecurity to protect networks from possible cyber attacks.  \nIn recent years, the world of cyber security has become more turbulent, with a rise in the number of cyber-attacks that target businesses worldwide. For this reason, always new methodologies are needed to shield vital assets from hostile actors in reaction to this expanding danger.  \nRecently, an increasing focus on the use of Artificial Intelligence (AI) in cyber security. As a subset of artificial intelligence, machine learning algorithms can improve danger detection and automate procedures. Organizations may examine massive volumes of data in real-time, spot patterns suggestive of malicious behaviour, and take preemptive measures to reduce risks by utilizing machine learning algorithms.  \nIn this work, we propose ReTiNA-IDS, a framework  \nItal-IA 2024: 4th National Conference on Artificial Intelligence, orga nized by CINI, May 29-30, 2024, Naples, Italy  \n*Michele Loreti †  \nThese authors contributed equally.  \n$ [erik.murtaj@studenti.unicam.it](erik.murtaj@studenti.unicam.it) (E. Murtaj);  \n[fausto.marcantoni@unicam.it](fausto.marcantoni@unicam.it) (F. Marcantoni); [michele.loreti@unicam.it](michele.loreti@unicam.it) (M. Loreti); [michela.quadrini@unicam.it](michela.quadrini@unicam.it)[ ](michela.quadrini@unicam.it)(M. Quadrini); hansfriedrich.witschel@fhnw.ch (H. Witschel)  \n􀀚 0000-0002-7779-203X (F. Marcantoni); 0000-0003-3061-863X (M. Loreti); 0000-0003-0539-0290 (M. Quadrini);  \n0000-0002-8608-9039 (H. Witschel)  \n© 2024 Copyright for this paper by its authors. Use permitted under Creative Commons License Attribution 4 .0 International (CC BY 4 .0) .  \nCEUR ~~  ~~[Workshop](Workshop ceur-ws.org)[ ceur-ws.org](Workshop ceur-ws.org)[ ](Workshop ceur-ws.org)[Proceedings](Proceedings ISSN 1613-0073)[ ISSN 1613-0073](Proceedings ISSN 1613-0073)   \nthat integrates the CICFlowmeter tool with Machine Learning techniques to analyze real-time network traffic patterns and detect abnormalities that may suggest a possible intrusion. The integrated methodology, which is based on random forest and multi-layer networks, is based on selected features to enhance efficiency and scalability. To sel","cbCaimCqypEuCcyX","https://ap.wps.com/l/cbCaimCqypEuCcyX","pdf",1367040,1,6,"English","en",105,"# Introduction\n# Related Works\n# ReTiNA-IDS Framework\n# Evaluation Experiments\n# Conclusion","[{\"question\":\"What problem does the paper address in cybersecurity?\",\"answer\":\"It addresses the need for real-time detection of hostile actions to protect network infrastructures from cyber attacks.\"},{\"question\":\"What is ReTiNA-IDS and how does it work?\",\"answer\":\"ReTiNA-IDS is a framework that combines the CICFlowmeter tool with machine learning to analyze real-time traffic patterns and detect abnormal behavior that may indicate intrusion.\"},{\"question\":\"Which machine learning methods and dataset are used for training and feature selection?\",\"answer\":\"The approach uses random forest and multi-layer network models, with feature selection and training performed using the public dataset CSECICI-IDS2018.\"}]","Real-Time Intrusion Detection via Machine Learning Approaches | PDF",1785728498,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"real-time-intrusion-detection-via-machine-learning-approaches","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/real-time-intrusion-detection-via-machine-learning-approaches/120161/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address in cybersecurity?","Question",{"text":75,"@type":76},"It addresses the need for real-time detection of hostile actions to protect network infrastructures from cyber attacks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is ReTiNA-IDS and how does it work?",{"text":80,"@type":76},"ReTiNA-IDS is a framework that combines the CICFlowmeter tool with machine learning to analyze real-time traffic patterns and detect abnormal behavior that may indicate intrusion.",{"name":82,"@type":73,"acceptedAnswer":83},"Which machine learning methods and dataset are used for training and feature selection?",{"text":84,"@type":76},"The approach uses random forest and multi-layer network models, with feature selection and training performed using the public dataset CSECICI-IDS2018.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]