Home / Current Issue / Paper 1714847
AI Enhanced Intrusion Detection and Prevention Systems (IDS/IPS)
Subject area: Science,Engineering and Technology · Area of research: Computer Science
Abstract
The increasing sophistication of cyber threats necessitates a move beyond traditional signature-based intrusion detection systems (IDS) toward more dynamic, data-driven approaches. This paper provides a comprehensive review of machine learning (ML) techniques for real-time network anomaly detection, a critical capability for responding to fast-moving attacks. We analyzed key ML paradigms, including supervised, unsupervised and semi-supervised learning, highlighting their trade-offs, such as the need for labeled data versus the ability to detect zero-day threats. A comparative analysis of traditional ML models (e.g., Random Forest, SVM) and deep learning (DL) architectures (e.g., CNN, LSTM, Autoencoder) reveals that DL models consistently offer superior performance in handling the high-dimensional, complex nature of modern network traffic, albeit with greater computational demands. Finally, we discuss advanced architectures and future research directions, including federated learning for its privacy-preserving and scalable nature and Explainable AI (XAI) for fostering trust and providing actionable insights to human security analysts. The paper concludes that the future of network security lies in the development of hybrid, continuously adaptive systems that balance performance, privacy and interpretability to effectively counter evolving cyber threats.
Keywords
computer network, Anomaly Detection, Computer Networks Security, Networking
References
[1] M. Natkaniec, K. Kosek-Szott, S. Szott and G. Bianchi, "A Survey of Medium Access Mechanisms for Providing QoS in Ad-Hoc Networks," IEEE communications surveys & tutorials, vol. 15, no. 2, pp. 592-620, 2012.
[2] G. Sunkara, "The Role of AI and Machine Learning in Enhancing SD-WAN Performance," SAMRIDDHI: A Journal of Physical Sciences, Engineering and Technology, vol. 14, no. 4, pp. 1-9, 7 December 2022.
[3] M. Karakus and A. Durresi, "Quality of service (QoS) in software defined networking (SDN): A survey," Journal of Network and Computer Applications, vol. 80, no. 1, pp. 200-218, 15 February 2017.
[4] K. Bouraqia, E. Sabir, M. Sadik and L. Ladid, "Quality of experience for streaming services: measurements, challenges and insights," IEEE Access, vol. 8, no. 1, pp. 13341-13361, 2020.
[5] Z. Mammeri, "Framework for parameter mapping to provide end-to-end QoS guarantees in IntServ/DiffServ architectures," Computer Communications, vol. 28, no. 9, pp. 1074-1092, 2 June 2005.
[6] S. R. Lima, P. Carvalho and V. Freitas, "Admission control in multiservice IP networks: architectural issues and trends," IEEE Communications Magazine, vol. 45, no. 4, pp. 114-121, 16 April 2007.
[7] A. Mohamad and H. A. Hussein, "Control Dynamic System and Qos Manager Agent Over Ipv6 Networks: Intserv and Diffserv Approach in Access Nodes," ResearchSquare, vol. 1, no. 1, pp. 1-36, 2023.
[8] A. Bahnasse, F. E. Louhab, H. A. Oulahyane, M. Talea and A. Bakali, "Novel SDN architecture for smart MPLS traffic engineering- DiffServ aware management," Future Generation Computer Systems, vol. 87, no. 1, pp. 115-126, 1 October 2018.
[9] M. Radivojević and M. Petar, "Quality of Service Implementation," The Emerging WDM EPON, vol. 1, no. 1, pp. 35-66, 13 May 2017.
[10] L. Han, Y. Qu, L. Dong and R. Li, "Flow-Level QoS Assurance via IPv6 In-Band Signalling," in 27th Wireless and Optical Communication Conference (WOCC 2018), Hualien, Taiwan, 2018.
How to cite this paper
@article{1714847,
author = {Dr. Kismat Chhillar, Dr. Deepak Tomar, Prof. Saurabh Shrivastava},
title = {AI Enhanced Intrusion Detection and Prevention Systems (IDS/IPS)},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {9},
pages = {175-183},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1714847.pdf},
abstract = {The increasing sophistication of cyber threats necessitates a move beyond traditional signature-based intrusion detection systems (IDS) toward more dynamic, data-driven approaches. This paper provides a comprehensive review of machine learning (ML) techniques for real-time network anomaly detection, a critical capability for responding to fast-moving attacks. We analyzed key ML paradigms, including supervised, unsupervised and semi-supervised learning, highlighting their trade-offs, such as the need for labeled data versus the ability to detect zero-day threats. A comparative analysis of traditional ML models (e.g., Random Forest, SVM) and deep learning (DL) architectures (e.g., CNN, LSTM, Autoencoder) reveals that DL models consistently offer superior performance in handling the high-dimensional, complex nature of modern network traffic, albeit with greater computational demands. Finally, we discuss advanced architectures and future research directions, including federated learning for its privacy-preserving and scalable nature and Explainable AI (XAI) for fostering trust and providing actionable insights to human security analysts. The paper concludes that the future of network security lies in the development of hybrid, continuously adaptive systems that balance performance, privacy and interpretability to effectively counter evolving cyber threats.},
keywords = {computer network, Anomaly Detection, Computer Networks Security, Networking},
month = {March},
doi = {https://doi.org/10.64388/IREV9I9-1714847}
}