The increasing use of computer networks, cloud platforms, and connected digital services has created a growing need for intelligent and adaptive cybersecurity solutions. Traditional intrusion detection methods that mainly depend on predefined rules and known attack signatures may have difficulty identifying changing or previously unseen network threats. This paper presents an AI-Based Network Intrusion Detection System that applies machine learning to identify malicious network activities from structured traffic data. The proposed system uses the NSL-KDD dataset and a Random Forest classifier to distinguish normal network connections from attack traffic. Data preprocessing operations, including feature transformation, categorical encoding, normalization, and label conversion, are performed before classification. The trained model is integrated with a Flask-based web application that provides secure authentication, dataset uploading, intrusion prediction, visual analytics, prediction logs, and alert generation. An SQLite database is used to maintain user and prediction-related information. The implemented system was tested across authentication, dataset processing, prediction, result visualization, logging, alert generation, and logout functions, with the documented test cases successfully completed. The reported model evaluation includes accuracy, precision, recall, and F1-score, demonstrating the practical application of the proposed approach for automated network traffic analysis and intrusion detection.
Introduction
The text presents an AI-Based Network Intrusion Detection System (NIDS) designed to automatically identify malicious network activity using machine learning. It addresses the limitations of traditional intrusion detection systems, which primarily rely on fixed rules and known attack signatures and may struggle with new or modified threats.
The proposed system uses the NSL-KDD dataset to train a Random Forest classifier. Network data is first preprocessed through cleaning, categorical encoding, feature transformation, normalization, and label conversion. The trained model classifies network connections as either normal or malicious.
The machine-learning model is integrated into a Flask-based web application. Authenticated users can upload CSV network datasets, obtain intrusion predictions, and view results through dashboards. The system also maintains prediction logs and generates alerts when malicious traffic is detected. SQLite is used to store user, prediction, and alert information.
Main Objectives
Develop a machine-learning-based system for detecting malicious network traffic.
Preprocess network data and train a Random Forest classification model.
Integrate the model into a user-friendly Flask web application.
Provide dashboards, prediction logs, and intrusion alerts.
Create a modular platform that can later support real-time monitoring and advanced AI techniques.
Methodology
The system follows these main steps:
Collect and use labeled NSL-KDD network traffic data.
Clean and preprocess the data.
Encode categorical features and normalize numerical features.
Train and evaluate a Random Forest classifier.
Integrate the trained model into a Flask web application.
Allow authenticated users to upload CSV network data.
Classify traffic as normal or malicious.
Store predictions in an SQLite database.
Display results through dashboards, logs, and alerts.
Literature Findings
Previous research has explored machine learning, deep learning, ensemble learning, federated learning, and hybrid approaches for intrusion detection. Studies using Random Forest, CNNs, GAN-SMOTE, ConvLSTM, and other techniques demonstrate the potential of AI for detecting complex cyberattacks. However, challenges remain in handling false positives, unseen attacks, computational requirements, dataset diversity, and real-time deployment.
Existing vs. Proposed System
Traditional systems depend heavily on predefined rules and known signatures, requiring continuous updates and potentially missing unfamiliar attacks. The proposed system instead learns patterns from network data using machine learning and provides an integrated platform for automated detection, visualization, logging, and alert generation.
Tools and Technologies
The major technologies used are:
Python – core development and machine learning
Scikit-learn – Random Forest and preprocessing
Pandas & NumPy – data processing
Flask – web application framework
HTML, CSS, Bootstrap & JavaScript – user interface
SQLite – database
NSL-KDD – training and evaluation dataset
PyCharm – development environment
System Architecture
The system consists of a web interface, authentication layer, preprocessing module, Random Forest model, SQLite database, and output/alert module. Uploaded network data passes through preprocessing and classification before the results are stored and displayed to the Forest classification with a Flask web interface, database management, dashboards, logs, and alerts, the system reduces dependence user.
Conclusion
The AI-Based Network Intrusion Detection System was successfully developed to identify potentially malicious activities within network traffic using machine learning techniques. The system combines data preprocessing, a Random Forest classification model, Flask-based web functionality, and SQLite database management to provide an integrated intrusion detection platform. Network traffic data is processed before classification, allowing the trained model to categorize connections as normal or malicious. The web application provides secure authentication, dataset uploading, prediction results, dashboards, prediction logs, and intrusion alerts, making the detection process more organized and accessible. The documented testing results show that the implemented functional modules operated successfully, including user authentication, dataset processing, prediction, result visualization, database logging, and alert generation. Overall, the project demonstrates the practical integration of machine learning with a web-based security application for automated network traffic analysis and provides a foundation for further development of intelligent network intrusion detection solutions..
References
[1] A. U. Abeykoon, “Prompt Engineering: Techniques and Applications in Conversational AI,” 2024.
[2] M. Foruhandeh, Y. Man, R. Gerdes, M. Li, and T. Chantem, “SINGLE: Single-Frame Based Physical Layer Identification for Intrusion Detection and Prevention on In-Vehicle Networks,” 2019.
[3] M. Althunayyan, A. Javed, and O. Rana, “A Robust Multi-Stage Intrusion Detection System for In-Vehicle Network Security Using Hierarchical Federated Learning,” 2024.
[4] S. Kumar, A. Kumar, H. K., and R. Raghavendra, “Hybrid Intrusion Detection System Using GAN-SMOTE and Machine Learning Techniques for In-Vehicle Networks,” 2023.
[5] A. Falanga and L. Berardinelli, “Automotive Cybersecurity: Data-Driven Intrusion Detection System for In-Vehicle Networks,” 2022.
[6] J. Lee, K. Choi, and S. Kim, “RF-CAN: Random Forest-Based Intrusion Detection System for CAN Networks,” 2023.
[7] H.-C. Lin, P. Wang, K.-M. Chao, W.-H. Lin, and J.-H. Chen, “Using Deep Learning Networks to Identify Cyber Attacks on In-Vehicle Networks,” 2022.
[8] J. Yang, J. Hu, and T. Yu, “Federated AI-Enabled In-Vehicle Network Intrusion Detection for Internet of Vehicles,” 2022.
[9] L. Xing, K. Wang, H. Wu, H. Ma, and X. Zhang, “FL-MAAE: Intrusion Detection for IoV Using Federated Learning and Memory-Augmented Autoencoder,” 2023.
[10] E. Alalwany and I. Mahgoub, “Ensemble Learning-Based Real-Time Intrusion Detection System for In-Vehicle Networks,” 2024.
[11] J. Alsamiri and K. Alsubhi, “Federated Learning-Based Intrusion Detection Systems in the Internet of Vehicles: A Survey,” 2023.
[12] D. Basavaraj and S. Tayeb, “Towards a Lightweight Intrusion Detection Framework for In-Vehicle Networks,” 2022.
[13] K.-T. Cho and K. G. Shin, “Fingerprinting Electronic Control Units for Vehicle Intrusion Detection (CIDS),” 2016.
[14] M. M. Hasan, M. M. Islam, and M. M. Rahman, “An Intrusion Detection System Framework for In-Vehicle Networks Based on CAN-Bus Data,” 2023.
[15] A. Ahmed and H. H. Salem, “Integrated Vehicle Cybersecurity: Threat Modeling and Intrusion Detection for In-Vehicle Networks,” 2022.