A Host-Based Multi Module Intrusion Detection Framework for Secure Public Wi-Fi Using Metadata Based Analysis and Real Time Risk Advisory
Abstract
Public Wi-Fi networks are widely used for convenient internet access, yet they expose users to major cyber security threats such as rogue access points, DNS manipulation, encrypted malware command and control (C2) communication and unsafe access to sensitive web applications. Traditional intrusion detection systems have failed to provide sufficient protection because they rely heavily on deep packet inspection, a method that is ineffective in modern encrypted environments and raises privacy concerns. This paper introduces a python and machine learning based privacy preserving, multi module IDS framework designed specifically for public Wi-Fi environments which is capable of detecting multiple threat vectors using only flow level metadata. For a solution to this ongoing problem, this system integrates four specialized detection modules: DNS anomaly detection, encrypted botnet and C2 activity detection, rogue access point (Evil Twin) identification, and sensitive web access (banking session) detection. Each module analyzes statistical and behavioral features such as packet size distributions, inter-arrival times, domain entropy, TLS fingerprints, and signal characteristics without inspecting packet payloads. A weighted risk fusion model is introduced to combine detection outputs and generate a unified risk score which is further translated into real time, context aware security advisories for end users. This framework is implemented as a software-based solution that operates at the network monitoring layer enabling real time analysis of encrypted traffic without requiring specialized hardware or modifications to user devices. Experimental evaluation using benchmark datasets and controlled test scenarios demonstrates strong detection performance for wireless layer threats and sensitive-session identification while maintaining low latency and efficient resource utilization, with reduced recall against low-rate encrypted C2 and DNS attacks identified as a documented limitation. A complementary capability analysis against a commercial endpoint detection and response (EDR) agent further shows that the framework provides visibility into wireless layer and contextual risks that endpoint-centric solutions do not cover. The results highlight the effectiveness of combining multiple metadata driven detection techniques into a unified framework, offering a practical and scalable approach for enhancing security in public Wi-Fi networks without compromising user privacy.