IMPROVING METHODS FOR DETECTING AND PREVENTING CYBERATTACKS IN COMPUTER NETWORKS
DOI:
https://doi.org/10.5281/zenodo.21801202Abstract
This study develops an adaptive hybrid framework for detecting and preventing cyberattacks in computer
networks. The framework combines signature matching, supervised classification, unsupervised anomaly detection, behavioral
correlation, asset context, and a safeguarded response policy. Its purpose is to preserve reliable detection when legitimate traffic
changes and when previously unseen attacks do not match existing rules. A design-science methodology was used together with
a controlled streaming emulation containing 120,000 training flows and 120,000 test flows distributed across baseline, benigndrift,
and mixed zero-day-like windows. In the emulation, the proposed method achieved 98.94% accuracy, 98.31% precision,
97.39% recall, a 97.85% F1-score, and a 0.55% false-positive rate. The strongest advantage appeared in the mixed/zero-day
window, where its F1-score reached 94.83%, compared with 73.90% for a static Random Forest and 57.26% for signature-only
detection. The results support a practical conclusion: prevention should be separated from detection and activated gradually
through logging, alerting, rate limiting, session interruption, and isolation, with higher-impact actions requiring corroboration
and rollback.
Keywords
network intrusion detection; intrusion prevention; concept drift; Random Forest; Isolation Forest; behavioral analytics; zero-day attack; adaptive threshold; cyber resilienceReferences
Verizon. 2026 Data Breach Investigations Report [Электронный ресурс]. – 2026. – URL: https://www.verizon.com/
business/resources/reports/dbir/ – Дата обращения: 24.07.2026.
Federal Bureau of Investigation. 2025 Internet Crime Report [Электронный ресурс]. – Washington, DC: Internet Crime
Complaint Center, 2026. – URL: https://www.fbi.gov/file-repository/2025_ic3report.pdf – Дата обращения: 24.07.2026.
National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. – Gaithersburg, MD:
National Institute of Standards and Technology, 2024. – (NIST CSWP 29). – DOI: https://doi.org/10.6028/NIST.CSWP.29.
Nelson A., Rekhi S., Souppaya M., Scarfone K. Incident Response Recommendations and Considerations for Cybersecurity
Risk Management: A CSF 2.0 Community Profile. – Gaithersburg, MD: National Institute of Standards and Technology, 2025. –
(NIST SP 800-61r3). – DOI: https://doi.org/10.6028/NIST.SP.800-61r3.
Sommer R., Paxson V. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection // 2010
IEEE Symposium on Security and Privacy. – 2010. – P. 305–316. – DOI: https://doi.org/10.1109/SP.2010.25.
A Survey of Network-Based Intrusion Detection Data Sets / M. Ring, S. Wunderlich, D. Scheuring [et al.] // Computers &
Security. – 2019. – Vol. 86. – P. 147–167. – DOI: https://doi.org/10.1016/j.cose.2019.06.005.
Canadian Institute for Cybersecurity. Intrusion Detection Evaluation Dataset (CIC-IDS2017) [Электронный ресурс]. –
Fredericton: University of New Brunswick, 2017. – URL: https://www.unb.ca/cic/datasets/ids-2017.html – Дата обращения:
07.2026.
Canadian Institute for Cybersecurity. CSE-CIC-IDS2018 on AWS [Электронный ресурс]. – Fredericton: University of
New Brunswick, 2018. – URL: https://www.unb.ca/cic/datasets/ids-2018.html – Дата обращения: 24.07.2026.
Moustafa N., Slay J. UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems // 2015
Military Communications and Information Systems Conference (MilCIS). – 2015. – P. 1–6. – DOI: https://doi.org/10.1109/
MilCIS.2015.7348942.
Breiman L. Random Forests // Machine Learning. – 2001. – Vol. 45, No. 1. – P. 5–32. – DOI: https://doi.
org/10.1023/A:1010933404324.
Liu F. T., Ting K. M., Zhou Z.-H. Isolation Forest // 2008 Eighth IEEE International Conference on Data Mining. – 2008.
– P. 413–422. – DOI: https://doi.org/10.1109/ICDM.2008.17.
Lundberg S. M., Lee S.-I. A Unified Approach to Interpreting Model Predictions // Advances in Neural Information
Processing Systems. – 2017. – Vol. 30. – DOI: https://doi.org/10.5555/3295222.3295230.
Seth S., Chahal K. K., Singh G. Concept Drift-Based Intrusion Detection for Evolving Data Stream Classification in IDS:
Approaches and Comparative Study // The Computer Journal. – 2024. – Vol. 67, No. 7. – P. 2529–2547. – DOI: https://doi.
org/10.1093/comjnl/bxae023.
García-Huitzitl E., Bustio-Martínez L., Cumplido R. Adaptive Intrusion Detection System: Hybrid K-Means and Random
Forest Approach with Concept Drift Detection // Computación y Sistemas. – 2025. – Vol. 29, No. 1. – P. 29–42. – DOI: https://doi.
org/10.13053/cys-29-1-5528.
Evolving Cybersecurity Frontiers: A Comprehensive Survey on Concept Drift and Feature Dynamics-Aware Machine
and Deep Learning in Intrusion Detection Systems / M. A. Shyaa, N. F. Ibrahim, Z. Zainol [et al.] // Engineering Applications of
Artificial Intelligence. – 2024. – Vol. 137. – Art. 109143. – DOI: https://doi.org/10.1016/j.engappai.2024.109143.
Open Information Security Foundation. Suricata IPS Concept Documentation [Электронный ресурс]. – 2026. – URL:
https://docs.suricata.io/en/latest/ips/ips-concept.html – Дата обращения: 24.07.2026.
MITRE. MITRE ATT&CK Enterprise Matrix [Электронный ресурс]. – 2026. – URL: https://attack.mitre.org/matrices/
enterprise/ – Дата обращения: 24.07.2026.
Rose S., Borchert O., Mitchell S., Connelly S. Zero Trust Architecture. – Gaithersburg, MD: National Institute of Standards
and Technology, 2020. – (NIST SP 800-207). – DOI: https://doi.org/10.6028/NIST.SP.800-207.

