Early detection of cyberattacks remains a major challenge in enterprise networks due to encrypted traffic, protocol diversity, and highly dynamic service behavior. This study evaluates a machine learning-based intrusion detection system trained on real enterprise traffic captured over 20 working days under operational conditions. A total of 1,163,014 packets were collected and complemented with controlled attack traffic, including DDoS, brute force, botnet, SQL injection, port scanning, privilege escalation, and service exploitation scenarios. After flow-based feature extraction and preprocessing, six supervised learning models were evaluated under the same data partition and validation settings. Among them, Random Forest achieved the best overall performance, with precision, recall, and F1-score above 0.999 and an AUC of 0.9994 on the collected dataset. These findings suggest that training with real traffic can improve IDS performance under realistic enterprise conditions. However, further validation across additional organizations and time periods is required to confirm generalizability.
Chinchay et al. (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: