A Supervised Machine Learning Framework for Intrusion Detection Using NSL-KDD Dataset and Ensemble Classification Models

Authors

  • Khtam Al-Meyah Department of Architectural Engineering, College of Engineering, University of Basrah , Iraq.

DOI:

https://doi.org/10.29304/jqcsm.2026.18.32777

Keywords:

Supervised Learning, Network Traffic Analysis, Anomaly Detection, Cyber Threat Detection, Classification Algorithms, Model Evaluation

Abstract

We propose a supervised machine learning-based approach for intrusion detection using the NSL-KDD dataset. The primary aim is to develop and compare a reproducible offline Intrusion Detection System (IDS) that can classify normal network traffic against intrusions using experimental settings. The methodology encompasses the data cleaning, encoding of categorical features, scaling, balancing of class distribution, model building and evaluation through a common evaluation framework.

We tested five supervised learning models: Logistic Regression, Decision Tree, Random Forest, Support Vector Machine, and K-Nearest Neighbors. The models are evaluated using accuracy, precision, recall, F1-score, ROC-AUC and false positive rate. The experimental results demonstrated that the best performance was achieved with the Random Forest classifier in terms of 97.2% accuracy, 97.6% precision, 96.9% recall, 97.2% F1-score, and 0.991 ROC-AUC, with the lowest false positive rate (2.1%). This suggests that ensemble classification techniques can achieve decent performance for intrusion detection experiments, with the aid of these census-based preprocessing and stratification procedures.

The research findings show Random Forest is the best choice among the tested algorithms for the proposed IDS framework, and similar preprocessing, cross-validation and security-related metrics enhance the reliability and repeatability of machine learning-based intrusion detection studies.

Downloads

Download data is not yet available.

References

World Economic Forum. (2025). Global Cybersecurity Outlook 2025 (in collaboration with Accenture). World Economic Forum.

European Union Agency for Cybersecurity (ENISA). (2024). ENISA Threat Landscape 2024. ENISA.

Verizon. (2024). 2024 Data Breach Investigations Report (DBIR). Verizon.

Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. doi:10.1109/COMST.2015.2494502

Mishra, P., Varadharajan, V., Tupakula, U. K., & Pilli, E. S. (2019). A detailed investigation and analysis of using machine learning techniques for intrusion detection. IEEE Communications Surveys & Tutorials, 21(1), 686–728. doi:10.1109/COMST.2018.2847722

Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), 4396. doi:10.3390/app9204396

Kocher, G., & Kumar, G. (2021). Machine learning and deep learning methods for intrusion detection systems: Recent developments and challenges. Soft Computing, 25, 9731–9763. doi:10.1007/s00500-021-05893-0

Pinto, A., Herrera, L.-C., Donoso, Y., & Gutierrez, J. A. (2023). Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure. Sensors, 23(5), 2415. doi:10.3390/s23052415

Thakkar, A., & Lohiya, R. (2020). A review of the advancement in intrusion detection datasets. Procedia Computer Science, 167, 636–645. doi:10.1016/j.procs.2020.03.330

Widodo, A. O., Setiawan, B., & Indraswari, R. (2024). Machine learning-based intrusion detection on multi-class imbalanced dataset using SMOTE. Procedia Computer Science, 234, 578–583. doi:10.1016/j.procs.2024.03.042

Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), 4396. https://doi.org/10.3390/app9204396

Mishra, P., Varadharajan, V., Tupakula, U. K., & Pilli, E. S. (2019). A detailed investigation and analysis of using machine learning techniques for intrusion detection. IEEE Communications Surveys & Tutorials, 21(1), 686–728. https://doi.org/10.1109/COMST.2018.2847722

Pinto, A., Gonçalves, G., & Silva, S. (2023). Survey on intrusion detection systems based on machine learning techniques. Sensors, 23(5), 2415. https://doi.org/10.3390/s23052415

Kocher, G., & Kumar, G. (2021). Machine learning and deep learning methods for intrusion detection systems. Soft Computing, 25, 9731–9763. https://doi.org/10.1007/s00500-021-05893-0

Hozouri, A., Mirzaei, A., & Effatparvar, M. (2025). Advances in intrusion detection systems using machine learning. Discover Artificial Intelligence, 5, 314.

Sarhan, M., Layeghy, S., Moustafa, N., Gallagher, M., & Portmann, M. (2024). Feature extraction for ML-based intrusion detection. Digital Communications and Networks, 10(1), 205–216.

Umar, A., Mahmoud, M. A., et al. (2025). Preprocessing techniques for ML-based IDS. arXiv preprint arXiv:2507.13314.

Thakkar, A., & Lohiya, R. (2020). Advancement in intrusion detection datasets. Procedia Computer Science, 167, 636–645.

Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset (CICIDS2017). ICISSP Proceedings.

Moustafa, N., & Slay, J. (2015). UNSW-NB15 dataset for network intrusion detection. MilCIS Conference Proceedings

Moustafa, N., & Slay, J. (2016). Evaluation of network anomaly detection systems using UNSW-NB15 dataset. Information Security Journal, 25(1–3), 18–31.

Shanmugam, V., Razavi-Far, R., & Hallaji, E. (2025). Addressing class imbalance in intrusion detection. Electronics, 14(1), 69.

Ajagbe, S. A., Awotunde, J. B., & Florez, H. (2024). Intrusion Detection: A Comparison Study of Machine Learning Models Using Unbalanced Dataset. SN Computer Science, 5, 1028. https://doi.org/10.1007/s42979-024-03369-0

Hamidou, S. T., & Mehdi, A. (2025). Enhancing IDS performance through a comparative analysis of Random Forest, XGBoost, and Deep Neural Networks. Machine Learning with Applications, Article 100738. https://doi.org/10.1016/j.mlwa.2025.100738

Waghmode, P., Kanumuri, M., El-Ocla, H., & Boyle, T. (2025). Intrusion detection system based on machine learning using least square support vector machine. Scientific Reports, 15, 12066. https://doi.org/10.1038/s41598-025-95621-7

Maodah, K. A., Alhomdy, S., & Thabit, F. (2025). Detecting intrusions in cloud-based ensembles: evaluating voting and stacking methods with machine learning classifiers. Frontiers in Computer Science, 7, 1623375. https://doi.org/10.3389/fcomp.2025.1623375

Downloads

Published

2026-09-30

How to Cite

Al-Meyah, K. (2026). A Supervised Machine Learning Framework for Intrusion Detection Using NSL-KDD Dataset and Ensemble Classification Models. Journal of Al-Qadisiyah for Computer Science and Mathematics, 18(3), Comp 108–122. https://doi.org/10.29304/jqcsm.2026.18.32777

Issue

Section

Computer Articles