NETWORK INTRUSION DETECTION USING MACHINE LEARNING ALGORITHMS ON THE NSL-KDD DATASET: A COMPARATIVE EXPERIMENTAL STUDY
http://doi.org/10.71284/jasem202614
DOI:
https://doi.org/10.71284/jasem202614Keywords:
Intrusion Detection System, NSL-KDD, Machine Learning, Network Security, Classification, Random Forest, Comparative EvaluationAbstract
The automatic detection of malicious activity in network traffic is one of the most critical components of today’s cybersecurity infrastructure. This study presents a reproducible experimental comparison that evaluates the binary classification performance—specifically, the ability to distinguish between normal and attack traffic—of three different machine learning classifiers (Logistic Regression, Decision Tree, and Random Forest) on the NSL-KDD dataset, which is widely used in the attack detection systems literature. To this end, a common Python evaluation pipeline was established, consisting of steps such as converting categorical features (e.g., protocol type, service, flags) to numerical form, standardizing the features, performing stratified training/test splits, and evaluating the models using metrics such as accuracy, precision, sensitivity, F1-score, and ROC-AUC metrics. The experimental results showed that the Random Forest model achieved the highest performance with 99.90% accuracy, a 99.89% F1-score, and an AUC of 1.00; this superiority was found to be statistically significant at p <0.001 and was confirmed to be robust via 5-fold cross-validation. The results obtained quantitatively demonstrate the extent to which tree-based ensemble methods offer an advantage over linear models in NSL-KDD and show that the common evaluation protocol used can be easily extended to different datasets and classifiers.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Applied Science & Engineering Materials

This work is licensed under a Creative Commons Attribution 4.0 International License.