[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119830-en":3,"doc-seo-119830-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119830,8796095360427,"Lucas Martin","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",6,"Technology","Zero-day Network Intrusion Detection using Machine Learning Approach","Zero-day network attacks pose an increasing global cybersecurity threat as adversaries exploit previously unknown weaknesses in networked systems. Detecting such intrusions depends on analyzing network traffic, yet inadequate feature selection and model limitations can cause poor detection quality, prolonged compromises, and high false alarm rates. This work presents a machine learning solution for zero-day network intrusion detection that integrates an anomaly-based extended isolation forest method with the BAT algorithm and Nevergrad, evaluated on 5G traffic to detect known and unknown attacks while reducing false alarms.","Zero-day Network Intrusion Detection using Machine Learning Approach  \nNaushad Alam1, Muqeem Ahmed2  \n1Department of Computer Science & Information Technology  \nMaulana Azad National Urdu University  \nHyderabad-500032  \n[Email-alamnaushad290@gmail.com](Email-alamnaushad290@gmail.com)  \n2Department of Computer Science & Information Technology  \nMaulana Azad National Urdu University  \nHyderabad-500032  \n[Email-muqeem.ahmed@gmail.com](Email-muqeem.ahmed@gmail.com)  \nAbstract-Zero-day network attacks are a growing global cybersecurity concern. Hackers exploit vulnerabilities in network systems, making network traffic analysis crucial in detecting and mitigating unauthorized attacks. However, inadequate and ineffective network traffic analysis can lead to prolonged network compromises. To address this, machine learning-based zero-day network intrusion detection systems (ZDNIDS) rely on monitoring and collecting relevant information from network traffic data. The selection of pertinent features is essential for optimal ZDNIDS performance given the voluminous nature of network traffic data, characterized by attributes. Unfortunately, current machine learning models utilized in this field exhibit inefficiency in detecting zero-day network attacks, resulting in a high false alarm rate and overall performance degradation. To overcome these limitations, this paper introduces a novel approach combining the anomaly-based extended isolation forest algorithm with the BAT algorithm and Nevergrad. Furthermore, the proposed model was evaluated using 5G network traffic, showcasing its effectiveness in efficiently detecting both known and unknown attacks, thereby reducing false alarms when compared to existing systems. This advancement contributes to improved internet security.  \nKeywords: Cybersecurity; Zero-day attack; BAT algorithm; Nevergrad.  \nI. INTRODUCTION  \nIn the technological era we live in, the Internet has become a necessary tool for business, education, and entertainment. The Internet has become a vital part of our dayto-day routines. Today, it is regarded as one of the most critical elements of the modern business landscape [1] . Network usage is on the rise, which carries with it the risk of attack. Keeping systems and networks secure is getting harder every year. Protecting against threats in real time is a challenging endeavor, and one of the most important aspects of cyber defense is reducing false alarm rates. According to the report [2], the number of vulnerabilities discovered each year has been growing continuously, with a total of 233,758 new vulnerabilities discovered in 2022 alone. The number of exploits has also been continually increasing, with 18.3 million discovered in 2022, in which phishing attack variants had the highest occurrence (41%), followed by malware and ransomware attacks (26%) . The data suggests that zero days have been increasingly popular among attackers in recent years, with 192 zero days found in 2022. This is a huge increase over previous years.  \nCybersecurity safeguards against attacks, data loss, and unauthorized access for internet-connected devices such as networks, computers, apps, and computers. [3] . The intrusion  \ndetection system (IDS) is a crucial component of cybersecurity systems. Its purpose is to detect, analyze, and identify unauthorized intrusions by examining data collected from network devices. [4] . There has been a significant increase in research on network intrusion detection over the past few years, and there are numerous opportunities to advance the state-ofthe-art in detecting and preventing network-based attacks, despite significant progress and a substantial corpus of work [5] . IDSs are programs that continuously monitor computer networks for harmful activities. Unauthorized attempts to steal sensitive information, censorship of network protocols, or anyother breach of network security protocols are examples of such operations. IDSs provide an additional layer of prote","cbCaiuPJPJ51Wrol","https://ap.wps.com/l/cbCaiuPJPJ51Wrol","pdf",331130,1,8,"English","en",105,"# Introduction\n## Cybersecurity threat landscape and zero-day popularity\n## Intrusion detection systems and detection types\n## Anomaly-based detection and machine learning motivations","[{\"question\":\"Why is network traffic analysis crucial for zero-day intrusion detection?\",\"answer\":\"Zero-day attacks exploit vulnerabilities not present in known patterns. Monitoring network traffic enables detection of unauthorized behaviors even when attacks are unknown.\"},{\"question\":\"What are the main limitations of current machine learning models for zero-day detection?\",\"answer\":\"Many models show inefficiency, leading to a high false alarm rate and degraded overall performance.\"},{\"question\":\"How does the proposed approach improve detection performance?\",\"answer\":\"It combines an anomaly-based extended isolation forest algorithm with the BAT algorithm and Nevergrad, then evaluates the model on 5G network traffic to detect both known and unknown attacks while reducing false alarms.\"}]","Zero-day Network Intrusion Detection using Machine Learning Approach | PDF",1785726534,20,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"zero-day-network-intrusion-detection-using-machine-learning-approach","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/zero-day-network-intrusion-detection-using-machine-learning-approach/119830/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is network traffic analysis crucial for zero-day intrusion detection?","Question",{"text":75,"@type":76},"Zero-day attacks exploit vulnerabilities not present in known patterns. Monitoring network traffic enables detection of unauthorized behaviors even when attacks are unknown.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the main limitations of current machine learning models for zero-day detection?",{"text":80,"@type":76},"Many models show inefficiency, leading to a high false alarm rate and degraded overall performance.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the proposed approach improve detection performance?",{"text":84,"@type":76},"It combines an anomaly-based extended isolation forest algorithm with the BAT algorithm and Nevergrad, then evaluates the model on 5G network traffic to detect both known and unknown attacks while reducing false alarms.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":119,"show_sort_weight":120,"slug":121},"Research & Report",30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":29,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":29,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]