Benchmarking Machine Learning Models for Intrusion Detection in Higher Education Networks Using CIC-IDS2017
Keywords:
CIC-IDS2017, cybersecurity, , intrusion detection, machine learningAbstract
The security of university networks faces an increase in attack surfaces due to the high dependence on digital services. Machine learning-based Intrusion Detection System (IDS) is one of the approaches to recognize benign and malicious traffic patterns. This study analyzes the benchmark machine learning model in the CIC-IDS2017 dataset through a literature study approach and comparative analysis. The models compared include Decision Tree, Random Forest, Support Vector Machine, Naive Bayes, Artificial Neural Network, as well as additional benchmarks XGBoost, KNN, and Logistic Regression. Evaluation parameters include accuracy, precision, recall, F1-score, false positive, false negative, and class distribution. The benchmark results showed that Random Forest achieved an accuracy of 99.67% with precision, recall, and malicious class F1-scores of 99.90%, 99.67%, and 99.67%, respectively in one of the published configurations. Another comparative study reported that XGBoost and Random Forest achieved 99.96% accuracy in their experimental configurations. Analysis of the class distribution showed a strong imbalance so that accuracy was not sufficient to assess the effectiveness of the IDS. The study recommends macro-F1 evaluation, per-class recall, false negative, and testing on more representative data before the model is used in a college production environment.
References
I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” Proc. ICISSP, 2018.
Canadian Institute for Cybersecurity, “Intrusion Detection Evaluation Dataset (CIC-IDS2017),” University of New Brunswick, dataset documentation.
“Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection Using Progressive Dataset,” Symmetry, 2023.
National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” NIST Cybersecurity White Paper 29, 2024.
K. Rigopoulos, S. Quinn, C. Pascoe, A. Mahn, and D. Topper, “NIST Cybersecurity Framework 2.0: Resource & Overview Guide,” NIST SP 1299, 2024.
“Multi-Attack Intrusion Detection System for Software-Defined Internet of Things Network,” comparative study using CICIDS2017.
“Comparative Performance Evaluation of Machine Learning Algorithms for Cyber Intrusion Detection,” Preprints, 2024.
R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symp. Security and Privacy, 2010, pp. 305–316, doi: 10.1109/SP.2010.25.
M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. IEEE Symp. Computational Intelligence for Security and Defense Applications (CISDA), 2009, pp. 1–6, doi: 10.1109/CISDA.2009.5356528.
K. Shaukat, S. Luo, V. Varadharajan, I. A. Hameed, and M. Xu, “A survey on machine learning techniques for cyber security in the last decade,” IEEE Access, vol. 8, pp. 222310–222354, 2020, doi: 10.1109/ACCESS.2020.3041951.
R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525–41550, 2019, doi: 10.1109/ACCESS.2019.2895334.
Z. Ahmad, A. S. Khan, C. W. Shiang, J. Abdullah, and F. Ahmad, “Network intrusion detection system: A systematic study of machine learning and deep learning approaches,” Trans. Emerging Telecommun. Technol., vol. 32, no. 1, Art. no. e4150, 2021, doi: 10.1002/ett.4150.
M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study,” J. Inf. Security Appl., vol. 50, Art. no. 102419, 2020, doi: 10.1016/j.jisa.2019.102419.
S. Gamage and J. Samarabandu, “Deep learning methods in network intrusion detection: A survey and an objective comparison,” J. Network and Computer Applications, vol. 169, Art. no. 102767, 2020, doi: 10.1016/j.jnca.2020.102767.
Helmiawan, M. A., Herdiana, D., Firmansyah, E., Sholihah, A. I. N., Putri, S. W., & Septiana, S. (2025, September). Cybersecurity Awareness and Its Impact on the Association Between Technology Use and Adolescent Mental Health. In 2025 13th International Conference on Cyber and IT Service Management (CITSM) (pp. 1-6). IEEE.
N. Shone, T. N. Nguyen, P. D. Vu, and Q. Shi, “A deep learning approach to network intrusion detection,” IEEE Trans. Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41–50, 2018, doi: 10.1109/TETCI.2017.2772792.
K. He, D. S. Kim, and M. R. Asghar, “Adversarial machine learning for network intrusion detection systems: A comprehensive survey,” IEEE Commun. Surveys Tuts., vol. 25, no. 1, pp. 538–566, 2023, doi: 10.1109/COMST.2022.3233793.
T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2016, pp. 785–794, doi: 10.1145/2939672.2939785.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Infoman's : Jurnal Ilmu-ilmu Informatika dan Manajemen

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
![]()
This work is licensed under a Creative Commons Attribution 4.0 International License.








