Skip to content
Open access

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

Sep 2026 · Information · 0 citations · 31 references

Abstract

Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space. An anti-data-leakage protocol (stratified partitioning, post-split normalization, five-fold cross-validation, and a SHA-1 cryptographic membership audit of an 8881 –flow test sub-sample) found no hash collisions between this sub-sample and the evaluation partitions. The framework added 32,670 authentic flows, increasing SQL Injection from 21 to 10,678, XSS from 652 to 13,212, and WBF from 1507 to 10,960. Among four evaluated ensemble models, LightGBM performed best, achieving 99.85% Accuracy, 99.85% F1-score, 99.29% Balanced Accuracy, and 97.87 ± 1.88% in five-fold cross-validation, improving detection rates by 44.9% (XSS), 23.0% (WBF), and 16.6% (SQL Injection) over the original dataset. A volume-matched ablation study showed comparable aggregate accuracy to synthetic balancing methods (SMOTE, SMOTE-Tomek), while geometric diversity analysis confirmed that authentic traffic occupies feature-space regions unreachable by interpolation, and chronological holdout evaluation confirmed generalization to unseen traffic (F1: 98.53–99.90%). Real-traffic enrichment thus offers a practical, more realistic complement to synthetic balancing for minority Web-attack detection.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.