Skip to content
Preprint

VPID: An Integrated Framework for Vulnerability Prioritization and Intrusion Detection in Enterprise Networks

Sep 2026 · 0 citations · 59 references
Computer Science

TL;DR

VPID, a lightweight framework for vulnerability prioritization and intrusion detection that consists of two principal modules: controlled vulnerability validation and intelligent intrusion defense, is designed and implemented.

Abstract

Small enterprises face increasingly serious threats to their internal networks but often lack the financial resources, computing capacity, and specialist staff required to deploy resource intensive security platforms. This paper designs and implements VPID, a lightweight framework for vulnerability prioritization and intrusion detection that consists of two principal modules: controlled vulnerability validation and intelligent intrusion defense. The first module uses OpenVAS for asset mapping and vulnerability identification, applies a decision tree to prioritize vulnerabilities, and employs a rule engine to generate targeted validation payloads. The second module captures network traffic using Scapy, analyzes it through a detection pipeline that combines a decision tree with multinomial Naive Bayes, verifies traffic assessed as high risk using Snort rules, and performs blocking and alerting through iptables. The evaluation uses 550,000 network flow samples containing normal and attack traffic for detector training, together with 15,000 labeled vulnerability records. On the vulnerability ranking test set, the decision tree achieves a precision of 91.8%, a recall of 89.5%, and an F1 score of 90.6%. On an independent test set containing 55,000 traffic samples, the combined detection pipeline achieves a precision of 94.5%, a recall of 88.3%, and an F1 score of 91.3%, while maintaining a false positive rate below 1.5%.

View source

Similar papers

Open access Aug 2026

Application of C4.5 Decision Tree Algorithm for Detecting Cyber Attacks Using IDS

This work constructs a web-based Intrusion Detection System prototype by training an entropy-based Decision Tree classifier, conceptually grounded in the C4.5 framework, on the NSL-KDD benchmark.

Daniel Erick Witopo, Hartana Wijaya · 0 citations
Open access 2026

Intrusion Detection System using NSL-KDD Dataset and Decision Tree Machine Learning Algorithm

A firewall is designed to filter traffic, block unauthorized access, and allow authorized access. Modern network hardware contains vulnerabilities that can be exploited by attackers to compromise network security. The aim of this project is to propose an efficient machine learning model to analyze the vulnerabilities i...

Victor Somadina Nd-Asogu, J. O. Fatokun, Chukwudi Anthony Udemba et al. · 0 citations
Open access Aug 2026

Automated Network Intrusion Detection for Internet of Things Security Enhancements

As interconnected devices increasingly transmit personal and sensitive data, security attacks are becoming more sophisticated and prevalent, highlighting the critical need for effective security solutions in Internet of Things (IoT) environments. An automated Network Intrusion Detection (NID) system plays a vital role...

Rangu Shashidhar, M. Raju · 1 citation
Open access Jul 2026

Toward Transparent Intrusion Detection Systems: An Explainable Ai Approach For Network Security

The growth in use of machine-learning based intrusion detection systems (IDS), however, also raises critical issues of transparency, trust, and accountability due to the fact that most of the top performing models are "black box" models. Lack of ability to provide explanation of detection decisions severely limits the...

Clinton Amponsah, B. Kyiewu, Andrew Oppong-Asante et al. · 0 citations
Preprint Aug 2026

A Lifecycle-Oriented Detection and Defense Framework for Price Manipulation Attacks in DeFi

Aiming at frequent oracle price manipulation attacks in Decentralized Finance (DeFi), this paper investigates attack patterns, vulnerability types, risk assessment, automated detection, and defense strategies. Based on Oracle lifecycle theory, a three-layer attack tree covering the physical, protocol, and application l...

Xing-Yu Xiong, Chang Liu, Xiaoqi Li · 0 citations
Open access Aug 2026

Enhancing Network Security with a Hybrid Intrusion Detection System Using SVM

A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.

Gaurav Kishor Saxena, Shambhu Dayal Sahu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.