A A COMPARATIVE REVIEW OF ZERO-DAY-LIKE ATTACK DETECTION MODELS BASED ON NETWORK TRAFFIC ANOMALY ANALYSIS: AN EXPERIMENT WITH A HYBRID AUTOENCODER AND ISOLATION FOREST MODEL
Downloads
Published:
2026-07-08Issue:
Vol. 1 No. 1 (2026): 2026_1Section:
ArticlesArticle language:
RussianViews:
10Downloads:
13Keywords:
intrusion detection system (IDS), zero-day attacks, network anomaly detection, machine learning, hybrid model, Autoencoder, Isolation ForestAbstract
The increasing complexity and frequency of network attacks, especially zero-day attacks, pose enormous challenges for traditional signature-based intrusion detection tools. This study proposes a hybrid approach based on an autoencoder and isolation forest to detect unknown attacks on network traffic. The CIC-IDS2017 dataset, which contains over 2 million labels of normal and malicious traffic, was used for the experiment. Data preprocessing included feature normalization, gap handling, and label binarization. The autoencoder was trained on normal traffic to understand standard network behavior, while isolation forest was used to detect rare deviations in traffic. When an anomaly was detected, the hybrid model labeled all traffic as anomalous. Precision, recall, F1-score, and ROC-AUC metrics were used to evaluate the model. Experimental results showed that the proposed hybrid method, based on the two models used, provides higher detection rates for first-day attack similarities compared to single models with a comparable false positive rate. These results confirm the feasibility of combining multiple models for intrusion detection tasks.
License
Copyright (c) 2026 Нуртас Куанышбай, Алтынбек Шарипбай

This work is licensed under a Creative Commons Attribution 4.0 International License.