Home / Current Issue / Paper 1712370
AI-Driven Intelligent Firewall for Real-Time Intrusion Detection Using XGBoost and CIC-IDS-2017 Dataset
Subject area: Science,Engineering and Technology · Area of research: Cyber Security
Abstract
Network security remains a critical challenge due to increasingly sophisticated cyberattacks. Traditional firewalls employing static rules and signature-based detection prove ineffective against novel and evolving threats. This paper presents an artificial intelligence-driven intelligent firewall system capable of detecting multiple attack types in real-time using machine learning techniques. We preprocessed, cleaned, normalized, and merged network flow data from the CIC-IDS-2017 dataset, specifically utilizing Monday and Wednesday traffic captures. An XGBoost classifier was trained on extracted features, achieving enhanced accuracy in multi-class attack detection. A Flask-based web interface enables real-time CSV traffic prediction with immediate actionable results. The proposed system successfully identifies attacks including Port Scan, Distributed Denial of Service (DDoS), and Denial of Service (DoS) variants, producing labeled outputs for immediate firewall action. Experimental results demonstrate that machine learning-enhanced firewalls significantly outperform traditional rule-based systems in both adaptability and accuracy, validating their essential role in next-generation network security infrastructure.
Keywords
Intrusion Detection System, Machine Learning, XGBoost, Network Security, CIC-IDS-2017, Cybersecurity
References
[1] D. E. Denning, "An Intrusion-Detection Model," IEEE Transactions on Software Engineering, vol. SE-13, no. 2, pp. 222-232, Feb. 1987.
[2] A. L. Buczak and E. Guven, "A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection," IEEE Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153-1176, 2016.
[3] J. R. Forest, B. Anderson, T. Sharma, and D. R. Butts, "Ensemble-Based Intrusion Detection System," in Proc. IEEE International Conference on Machine Learning and Applications, 2018, pp. 1204-1211.
[4] S. Ahmed, Y. Lee, S. Hyun, and I. Koo, "A Survey of Network Intrusion Detection Systems: Techniques, Datasets and Challenges," IEEE Communications Surveys & Tutorials, vol. 17, no. 4, pp. 2045-2072, Fourth quarter 2015.
[5] K. Kumar, S. Gupta, and R. Singh, "Machine Learning Approaches for Intrusion Detection in Computer Networks: A Comparative Analysis," in Proc. International Conference on Computing, Communication and Automation (ICCCA), 2019, pp. 1-6.
[6] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization," in Proc. 4th International Conference on Information Systems Security and Privacy (ICISSP), 2018, pp. 108-116.
[7] T. Chen and C. Guestrin, "XGBoost: A Scalable Tree Boosting System," in Proc. 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785-794.
[8] R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, "Deep Learning Approach for Intelligent Intrusion Detection System," IEEE Access, vol. 7, pp. 41525-41550, 2019.
[9] M. Ring, S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, "A Survey of Network-based Intrusion Detection Data Sets," Computers \& Security, vol. 86, pp. 147-167, Sept. 2019.
[10] N. Moustafa and J. Slay, "UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems," in Proc. Military Communications and Information
How to cite this paper
@article{1712370,
author = {Shinde Hanumant Umesh, Naikwade Aditya Shivaji, Chiddarwar Shantanu Naresh, Prof. S. G. Ekdante, Prof. J. M. Shaikh},
title = {AI-Driven Intelligent Firewall for Real-Time Intrusion Detection Using XGBoost and CIC-IDS-2017 Dataset},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {2357-2362},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712370.pdf},
abstract = {Network security remains a critical challenge due to increasingly sophisticated cyberattacks. Traditional firewalls employing static rules and signature-based detection prove ineffective against novel and evolving threats. This paper presents an artificial intelligence-driven intelligent firewall system capable of detecting multiple attack types in real-time using machine learning techniques. We preprocessed, cleaned, normalized, and merged network flow data from the CIC-IDS-2017 dataset, specifically utilizing Monday and Wednesday traffic captures. An XGBoost classifier was trained on extracted features, achieving enhanced accuracy in multi-class attack detection. A Flask-based web interface enables real-time CSV traffic prediction with immediate actionable results. The proposed system successfully identifies attacks including Port Scan, Distributed Denial of Service (DDoS), and Denial of Service (DoS) variants, producing labeled outputs for immediate firewall action. Experimental results demonstrate that machine learning-enhanced firewalls significantly outperform traditional rule-based systems in both adaptability and accuracy, validating their essential role in next-generation network security infrastructure.},
keywords = {Intrusion Detection System, Machine Learning, XGBoost, Network Security, CIC-IDS-2017, Cybersecurity},
month = {November},
doi = {https://doi.org/10.64388/IREV9I5-1712370}
}