Open Access

A Review of Machine Learning Techniques for Network Intrusion Detection Systems

4 Assistant Professor Department of Computer Science and Applications Mandsaur (M.P.)

Abstract

Security researchers rely heavily on Network Intrusion Detection Systems (NIDS) to keep an eye on network traffic and notify administrators of any suspicious activities. The purpose of this paper is to offer a comprehensive overview of intrusion detection systems (IDS), including the following topics: fundamentals, kinds of IDS, methods for detecting intrusions in NIDS, the architecture of IDS, data pre-processing, and examples of ML techniques used in NIDS. This covers several detection methods, including signature-based, anomaly-based, specification-based, and behavior-based approaches, as well as their advantages and disadvantages in recognizing both existing and new cyber threats. The review also covers the architecture of NIDS which consists of network sensors, preprocessors, network traffic analysis, alert generation and security analysis. A variety of ML techniques, including supervised, unsupervised, semi-supervised, ensemble, and deep learning (DL) approaches, are being explored to improve the accuracy and adaptability of intrusion detection systems (IDS). Other applications such as DoS/DDoS attack detection, Malware detection, Botnets, Brute force attacks, Insider compromise, IoT compromise and Critical infrastructure threats are also shown. Despite all the challenges in terms of false positives, scalability, computational complexity, data quality, and novel attack styles, the features that ML can provide for intelligent, adaptive, and accurate intrusion detection systems are appealing.

Keywords

References

S. Kumar, P. Pathak, K. Agrawal, V. Goswami, and A. Mahindru, “Network Intrusion Detection System Using Machine Learning,” Lect. Notes Networks Syst., vol. 730 LNNS, pp. 735–743, 2023, doi: 10.1007/978-981-99-3963-3_56.
S. Singh, “Advancing Network Security in 5G: Leveraging the 5G-NIDD Dataset for Intrusion Detection and Mitigation,” in 2025 IEEE 12th International Conference on Cyber Security and Cloud Computing (CSCloud), IEEE, Nov. 2025, pp. 1–6. doi: 10.1109/CSCloud66326.2025.00055.
Y. Muni, “Advanced Multi-Protocol Label Switching (MPLS)-Enabled Networks: A Survey of Emerging Approaches Via Traffic Engineering,” Eng. Technol. J., vol. 11, no. 01, Jan. 2026, doi: 10.47191/etj/v11i01.22.
H. Liu and B. Lang, “Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey,” Appl. Sci., vol. 9, no. 20, p. 4396, Oct. 2019, doi: 10.3390/app9204396.
D. Moon, S. B. Pan, and I. Kim, “Host-based intrusion detection system for secure human-centric computing,” J. Supercomput., vol. 72, no. 7, pp. 2520–2536, 2016, doi: 10.1007/s11227-015-1506-9.
S. S. Dash, S. K. Nayak, and D. Mishra, “A review on machine learning algorithms,” Smart Innov. Syst. Technol., vol. 153, pp. 495–507, 2021, doi: 10.1007/978-981-15-6202-0_51.
K. K. Mohammed, “A Survey on Digital Health Care Data Analysis Techniques for Developing Machine Learning Models,” Int. J. Sci. Eng. Technol., vol. 13, no. 5, October, pp. 1–6, 2025, doi: :10.5281/zenodo.17339813.
S. Sah, “Machine Learning: A Review of Learning Types,” Neural Networks 152, vol. 7, no. 1, pp. 267–275, 2020, doi: 10.20944/preprints202007.0230.v1.
A. V. S. R. Dantuluri, “A Scalable Deep Learning Analytics Pipeline for Converting Longitudinal Real-World Data Into Predictive Disease Trajectories,” IEEE Access, vol. 14, pp. 24871–24878, 2026, doi: 10.1109/ACCESS.2026.3663571.
A. Joon, “Smart Predictive Maintenance: AI-Driven Adaptation for Industrial Equipment,” in 2025 IEEE North-East India International Energy Conversion Conference and Exhibition (NE-IECCE), IEEE, Jul. 2025, pp. 1–6. doi: 10.1109/NE-IECCE64154.2025.11183108.
L. Cheng and T. Yu, “A new generation of AI: A review and perspective on machine learning technologies applied to smart energy and electric power systems,” Int. J. Energy Res., vol. 43, no. 6, pp. 1928–1973, May 2019, doi: 10.1002/er.4333.
L. A. Yeruva, D. Singh, S. Suddala, N. Bhatt, and R. Uddin, “Augmented Data Management for Cache Performance, Cybersecurity, and Mobile Integration,” J. Comput. Mech. Manag., vol. 5, no. 3, pp. 280–293, June, Jun. 2026, doi: 10.57159/jcmm.5.3.26691.
A. Joon, B. K. R. Janumpally, A. Gogineni, and P. Chatterjee, “Efficient Large-Scale Intrusion Identification and Prevention in Distributed Cloud Networks Using Artificial Intelligence,” in 2025 5th International Conference on Intelligent Technologies (CONIT), IEEE, Jun. 2025, pp. 1–8. doi: 10.1109/CONIT65521.2025.11167760.
M. Aljanabi, M. A. Ismail, R. Hasan, and J. Sulaiman, “Intrusion Detection: A Review,” Mesopotamian J. Cyber Secur., vol. 2021, pp. 1–4, 2021, doi: 10.58496/MJCS/2021/001.
M. Ring, S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, “A survey of network-based intrusion detection data sets,” Comput. Secur., vol. 86, pp. 147–167, Sep. 2019, doi: 10.1016/j.cose.2019.06.005.
H. Satilmiş, S. Akleylek, and Z. Y. Tok, “A Systematic Literature Review on Host-Based Intrusion Detection Systems,” IEEE Access, vol. 12, pp. 27237–27266, 2024, doi: 10.1109/ACCESS.2024.3367004.
S. Remya, M. J. Pillai, C. Arjun, S. Ramasubbareddy, and Y. Cho, “Enhancing Security in LLNs Using a Hybrid Trust-Based Intrusion Detection System for RPL,” IEEE Access, vol. 12, pp. 58836–58850, 2024, doi: 10.1109/ACCESS.2024.3391918.
V. Rohilla, K. Rohilla, P. Kumar, and N. Jain, “Intrusion Detection in Network Traffic Using Feature Selection and Optuna-Based Machine Learning Optimization,” in 2026 3rd International Conference on Research Methodologies in Knowledge Management, Artificial Intelligence and Telecommunication Engineering (RMKMATE), IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/RMKMATE69073.2026.11518834.
H. Y. Kwon, T. Kim, and M. K. Lee, “Advanced Intrusion Detection Combining Signature-Based and Behavior-Based Detection Methods,” Electron., vol. 11, no. 6, pp. 1–19, 2022, doi: 10.3390/electronics11060867.
B. Al-Fuhaidi, Z. Farae, F. Al-Fahaidy, G. Nagi, A. Ghallab, and A. Alameri, “Anomaly‐Based Intrusion Detection System in Wireless Sensor Networks Using Machine Learning Algorithms,” Appl. Comput. Intell. Soft Comput., vol. 2024, no. 1, p. 2625922, Jan. 2024, doi: 10.1155/2024/2625922.
E. Hotellier, F. Sicard, J. Francq, and S. Mocanu, “Standard specification-based intrusion detection for hierarchical industrial control systems,” Inf. Sci. (Ny)., vol. 659, p. 120102, Feb. 2024, doi: 10.1016/j.ins.2024.120102.
C. Wang and H. Zhu, “Wrongdoing Monitor: A Graph-Based Behavioral Anomaly Detection in Cyber Security,” IEEE Trans. Inf. Forensics Secur., vol. 17, pp. 2703–2718, 2022, doi: 10.1109/TIFS.2022.3191493.
L. Diana, P. Dini, and D. Paolini, “Overview on Intrusion Detection Systems for Computers Networking Security,” 2025. doi: 10.3390/computers14030087.
A. Shamekhi, P. Shamsinejad Babaki, and R. Javidan, “An intelligent behavioral-based DDOS attack detection method using adaptive time intervals,” Peer-to-Peer Netw. Appl., vol. 17, no. 4, pp. 2185–2204, 2024, doi: 10.1007/s12083-024-01690-2.
Y. Hamid, S. Muthukumarasamy, and L. Journaux, “Machine Learning Techniques for Intrusion Detection: A Comparative Analysis,” 2016, pp. 1–6. doi: 10.1145/2980258.2980378.
M. Ozkan-Okay, R. Samet, Ö. Aslan, and D. Gupta, “A Comprehensive Systematic Literature Review on Intrusion Detection Systems,” IEEE Access, vol. 9, pp. 157727–157760, 2021, doi: 10.1109/ACCESS.2021.3129336.
B. E. Ricks, “Intrusion detection systems,” Phys. Secur. Saf. A F. Guid. Pract., no. 9, pp. 101–108, 2014, doi: 10.48175/ijarsct-17606.
A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, 2019, doi: 10.1186/s42400-019-0038-7.
P. Kumar, “A Zero Trust-Based Approach to Modern Cybersecurity Challenges in Software Development,” Int. J. Emerg. Res. Eng. Technol., vol. 6, no. 9, pp. 113–122, September, 2025.
B. Bin Sarhan and N. Altwaijry, “Insider Threat Detection Using Machine Learning Approach,” Appl. Sci., vol. 13, no. 1, p. 259, Dec. 2022, doi: 10.3390/app13010259.
M. M. Najafabadi, T. M. Khoshgoftaar, C. Kemp, N. Seliya, and R. Zuech, “Machine Learning for Detecting Brute Force Attacks at the Network Level,” in 2014 IEEE International Conference on Bioinformatics and Bioengineering, IEEE, Nov. 2014, pp. 379–385. doi: 10.1109/BIBE.2014.73.
J. M. Waghmare and M. M. Chitmogrekar, “A Review on Malware Detection Methods,” SAMRIDDHI A J. Phys. Sci. Eng. Technol., vol. 14, no. 01, pp. 38–43, 2022, doi: 10.18090/samriddhi.v14i01.6.
T. D. Adugna, A. Ramu, and A. Haldorai, A Review of Pattern Recognition and Machine Learning, vol. 4, no. 1. 2024. doi: 10.53759/7669/jmc202404020.
S. A. Moon, B. Maram, B. V Srinivasulu, and P. V. K. Reddy, “A Live Network Attack Detection System Employing Self-Adjusting and Interpretable Machine Learning Techniques,” in 2026 4th International Conference on Self Sustainable Artificial Intelligence Systems (ICSSAS), IEEE, May 2026, pp. 1177–1182. doi: 10.1109/ICSSAS68835.2026.11559485.
R. Rehyadd and P. Agarwal, “Performance Comparison of Machine Learning and Deep Learning Techniques for Detecting Network Intrusions,” in 2025 International Conference on Next Generation of Green Information and Emerging Technologies (GIET), IEEE, Aug. 2025, pp. 1–7. doi: 10.1109/GIET65294.2025.11234882.
S. Hiremath, R. D B, S. Singh, S. S V, and R. K R, “Machine Learning Models for Intrusion Detection System,” in 2025 IEEE 14th International Conference on Communication Systems and Network Technologies (CSNT), IEEE, Mar. 2025, pp. 235–238. doi: 10.1109/CSNT64827.2025.10967597.
R. S. Valasev, A. R. Priambodo, and R. N. Esti Anggraini, “Evaluating Contemporary Machine Learning and Deep Learning Strategies for Intrusion Detection,” in 2024 IEEE International Conference on Control & Automation, Electronics, Robotics, Internet of Things, and Artificial Intelligence (CERIA), IEEE, Oct. 2024, pp. 1–5. doi: 10.1109/CERIA64726.2024.10915015.
B. Li et al., “Enhancing Network Security: Machine Learning Evaluation for Intrusion Detection in Power Load Management System,” in 2024 5th International Conference on Information Science, Parallel and Distributed Systems (ISPDS), IEEE, May 2024, pp. 708–712. doi: 10.1109/ISPDS62779.2024.10667483.
K. Hemavathi and R. Latha, “Conditional Generative Adversarial Network with Optimal Machine Learning Based Intrusion Detection System,” in 2023 International Conference on Sustainable Communication Networks and Application (ICSCNA), IEEE, Nov. 2023, pp. 1176–1182. doi: 10.1109/ICSCNA58489.2023.10370325.
M. Bommy, T. Vivekanandan, Y. Sreeraman, D. Jagadeesan, C. Sunil Kumar, and G. Asha, “Mobile Ad Hoc Networks Supporting Adaptive Threat Detection through Intrusion Detection Effective Use of Machine Learning for Cyber Defense,” in 2023 International Conference on Innovative Computing, Intelligent Communication and Smart Electrical Systems (ICSES), IEEE, Dec. 2023, pp. 1–5. doi: 10.1109/ICSES60034.2023.10465320.

Similar Articles

1-10 of 51

You may also start an advanced similarity search for this article.