Website of D. Serikbayev EKTU
  • Font Size
    16px
    Website Colors
    Images

A A COMPARATIVE REVIEW OF ZERO-DAY-LIKE ATTACK DETECTION MODELS BASED ON NETWORK TRAFFIC ANOMALY ANALYSIS: AN EXPERIMENT WITH A HYBRID AUTOENCODER AND ISOLATION FOREST MODEL

Authors

Name Affiliation
Nurtas Kuanyshbay L.N. Gumilyov Eurasian National University
Altynbek Sharipbay L.N. Gumilyov Eurasian National University

Downloads

Published:

2026-07-08

Article language:

Russian

Views:

10

Downloads:

13

Keywords:

intrusion detection system (IDS), zero-day attacks, network anomaly detection, machine learning, hybrid model, Autoencoder, Isolation Forest

Abstract

The increasing complexity and frequency of network attacks, especially zero-day attacks, pose enormous challenges for traditional signature-based intrusion detection tools. This study proposes a hybrid approach based on an autoencoder and isolation forest to detect unknown attacks on network traffic. The CIC-IDS2017 dataset, which contains over 2 million labels of normal and malicious traffic, was used for the experiment. Data preprocessing included feature normalization, gap handling, and label binarization. The autoencoder was trained on normal traffic to understand standard network behavior, while isolation forest was used to detect rare deviations in traffic. When an anomaly was detected, the hybrid model labeled all traffic as anomalous. Precision, recall, F1-score, and ROC-AUC metrics were used to evaluate the model. Experimental results showed that the proposed hybrid method, based on the two models used, provides higher detection rates for first-day attack similarities compared to single models with a comparable false positive rate. These results confirm the feasibility of combining multiple models for intrusion detection tasks.

Author Biography

Altynbek Sharipbay

Doctor of Technical Sciences, Professor, Professor of the Department of Artificial Intelligence Technologies

ORCID: 0009-0000-5511-7466

Email: [email protected]

Kuanyshbay, N., & Sharipbay, A. (2026). A A COMPARATIVE REVIEW OF ZERO-DAY-LIKE ATTACK DETECTION MODELS BASED ON NETWORK TRAFFIC ANOMALY ANALYSIS: AN EXPERIMENT WITH A HYBRID AUTOENCODER AND ISOLATION FOREST MODEL: . EKTU Journal of Information Security and Cryptography, 1(1). Retrieved from https://journals.ektu.kz/jisc/article/view/1888