Benchmarking Machine Learning Models for Intrusion Detection in Higher Education Networks Using CIC-IDS2017

Authors

  • Moch Irwan Hermanto Irwan Universitas Islam Nusantara
  • Galih Universitas Islam Nusantara
  • Rudhi Wahyudi Febrianto Universitas Islam Nusantara
  • Siti Nur Universitas Teknologi Bandung

Keywords:

CIC-IDS2017, cybersecurity, , intrusion detection, machine learning

Abstract

The security of university networks faces an increase in attack surfaces due to the high dependence on digital services. Machine learning-based Intrusion Detection System (IDS) is one of the approaches to recognize benign and malicious traffic patterns. This study analyzes the benchmark machine learning model in the CIC-IDS2017 dataset through a literature study approach and comparative analysis. The models compared include Decision Tree, Random Forest, Support Vector Machine, Naive Bayes, Artificial Neural Network, as well as additional benchmarks XGBoost, KNN, and Logistic Regression. Evaluation parameters include accuracy, precision, recall, F1-score, false positive, false negative, and class distribution. The benchmark results showed that Random Forest achieved an accuracy of 99.67% with precision, recall, and malicious class F1-scores of 99.90%, 99.67%, and 99.67%, respectively in one of the published configurations. Another comparative study reported that XGBoost and Random Forest achieved 99.96% accuracy in their experimental configurations. Analysis of the class distribution showed a strong imbalance so that accuracy was not sufficient to assess the effectiveness of the IDS. The study recommends macro-F1 evaluation, per-class recall, false negative, and testing on more representative data before the model is used in a college production environment.

References

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” Proc. ICISSP, 2018.

Canadian Institute for Cybersecurity, “Intrusion Detection Evaluation Dataset (CIC-IDS2017),” University of New Brunswick, dataset documentation.

“Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection Using Progressive Dataset,” Symmetry, 2023.

National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” NIST Cybersecurity White Paper 29, 2024.

K. Rigopoulos, S. Quinn, C. Pascoe, A. Mahn, and D. Topper, “NIST Cybersecurity Framework 2.0: Resource & Overview Guide,” NIST SP 1299, 2024.

“Multi-Attack Intrusion Detection System for Software-Defined Internet of Things Network,” comparative study using CICIDS2017.

“Comparative Performance Evaluation of Machine Learning Algorithms for Cyber Intrusion Detection,” Preprints, 2024.

R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symp. Security and Privacy, 2010, pp. 305–316, doi: 10.1109/SP.2010.25.

M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. IEEE Symp. Computational Intelligence for Security and Defense Applications (CISDA), 2009, pp. 1–6, doi: 10.1109/CISDA.2009.5356528.

K. Shaukat, S. Luo, V. Varadharajan, I. A. Hameed, and M. Xu, “A survey on machine learning techniques for cyber security in the last decade,” IEEE Access, vol. 8, pp. 222310–222354, 2020, doi: 10.1109/ACCESS.2020.3041951.

R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525–41550, 2019, doi: 10.1109/ACCESS.2019.2895334.

Z. Ahmad, A. S. Khan, C. W. Shiang, J. Abdullah, and F. Ahmad, “Network intrusion detection system: A systematic study of machine learning and deep learning approaches,” Trans. Emerging Telecommun. Technol., vol. 32, no. 1, Art. no. e4150, 2021, doi: 10.1002/ett.4150.

M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study,” J. Inf. Security Appl., vol. 50, Art. no. 102419, 2020, doi: 10.1016/j.jisa.2019.102419.

S. Gamage and J. Samarabandu, “Deep learning methods in network intrusion detection: A survey and an objective comparison,” J. Network and Computer Applications, vol. 169, Art. no. 102767, 2020, doi: 10.1016/j.jnca.2020.102767.

Helmiawan, M. A., Herdiana, D., Firmansyah, E., Sholihah, A. I. N., Putri, S. W., & Septiana, S. (2025, September). Cybersecurity Awareness and Its Impact on the Association Between Technology Use and Adolescent Mental Health. In 2025 13th International Conference on Cyber and IT Service Management (CITSM) (pp. 1-6). IEEE.

N. Shone, T. N. Nguyen, P. D. Vu, and Q. Shi, “A deep learning approach to network intrusion detection,” IEEE Trans. Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41–50, 2018, doi: 10.1109/TETCI.2017.2772792.

K. He, D. S. Kim, and M. R. Asghar, “Adversarial machine learning for network intrusion detection systems: A comprehensive survey,” IEEE Commun. Surveys Tuts., vol. 25, no. 1, pp. 538–566, 2023, doi: 10.1109/COMST.2022.3233793.

T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2016, pp. 785–794, doi: 10.1145/2939672.2939785.

Downloads

Published

2026-08-31

How to Cite

Irwan, M. I. H., Galih, Wahyudi Febrianto, R., & Nur, S. (2026). Benchmarking Machine Learning Models for Intrusion Detection in Higher Education Networks Using CIC-IDS2017. Infoman’s : Jurnal Ilmu-Ilmu Informatika Dan Manajemen, 20(1), 34–40. Retrieved from https://ejournal.unsap.ac.id/index.php/infomans/article/view/3085

Issue

Section

Articles

Most read articles by the same author(s)

Obs.: This plugin requires at least one statistics/report plugin to be enabled. If your statistics plugins provide more than one metric then please also select a main metric on the admin's site settings page and/or on the journal manager's settings pages.