IJWMT Vol. 16, No. 5, 8 Oct. 2026
Cover page and Table of Contents: PDF (size: 1329KB)
PDF (1329KB), PP.428-446
Views: 0 Downloads: 0
Network Security, Port Scanning, Adaptive Entropy, Random Forest, Intrusion Detection System, Real-Time Detection
Network port scanning represents a critical reconnaissance phase preceding advanced cyber attacks and poses a significant threat to modern network infrastructures. Conventional signature-based detection systems and static threshold mechanisms are often ineffective in detecting stealthy and low-rate scanning activities in dynamic network environments. This paper proposes a hybrid intrusion detection approach that combines adaptive entropy-based filtering with a Random Forest classifier. The proposed method employs a sliding window mechanism to dynamically adjust detection thresholds based on statistical properties of network traffic, thereby improving adaptability under varying load conditions. Experimental evaluation conducted on the CIC-IDS2017 dataset demonstrates that the proposed model achieves a classification accuracy of 98.7% with a False Positive Rate (FPR) of 1.8%, outperforming both standalone entropy-based and machine learning-based approaches. In addition, the model maintains an average processing latency of 2.3 ms per packet, confirming its suitability for real-time deployment in high-speed network environments. The results indicate that the proposed hybrid approach effectively improves detection performance while maintaining low computational overhead, making it a practical solution for modern intrusion detection systems. However, the proposed approach has certain limitations, including reliance on traffic metadata and reduced effectiveness in encrypted environments.
Maruf Tojiyev Ruzikulovich, Bahtiyor Holmuhamedov Farkhodovich, Sofiyaxon Usmonova Alimovna, Jura Kuvandikov Tursunbayevich, "Real-Time Port Scanning Attack Detection Using Adaptive Entropy Analysis and Random Forest-based Hybrid Model", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 428-446, 2026. DOI:10.5815/ijwmt.2026.05.25
[1]O. H. Abdulganiyu, T. Ait Tchakoucht, and Y. K. Saheed, “A systematic literature review for network intrusion detection system (IDS),” International Journal of Information Security, vol. 22, pp. 1125–1162, 2023, doi: 10.1007/s10207-023-00682-2.
[2]A. Pinto, L.-C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on Intrusion Detection Systems Based on Machine Learning Techniques for the Protection of Critical Infrastructure,” Sensors, vol. 23, no. 5, Art. 2415, 2023, doi: 10.3390/s23052415.
[3]K. He, D. D. Kim, and M. R. Asghar, “Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey,” IEEE Communications Surveys & Tutorials, vol. 25, no. 1, pp. 538–566, 2023, doi: 10.1109/COMST.2022.3233793.
[4]A. Aldhaheri, F. Alwahedi, M. A. Ferrag, and A. Battah, “Deep learning for cyber threat detection in IoT networks: A review,” Internet of Things and Cyber-Physical Systems, vol. 4, pp. 110–128, 2024, doi: 10.1016/j.iotcps.2023.09.003.
[5]A. Ghaffari, N. Jelodari, S. Pouralish, N. Derakhshanfard, and B. Arasteh, "Securing internet of things using machine and deep learning methods: a survey," Cluster Computing, vol. 27, no. 7, pp. 9065-9089, 2024, doi: 10.1007/s10586-024-04509-0.
[6]D. Khasanov, M. Tojiyev and O. Primqulov, "Gradient descent in machine learning," 2021 International Conference on Information Science and Communications Technologies (ICISCT), Tashkent, Uzbekistan, 2021, pp. 1-3, doi: 10.1109/ICISCT52966.2021.9670169.
[7]L. Li, Y. Lu, G. Yang, and X. Yan, “End-to-End Network Intrusion Detection Based on Contrastive Learning,” Sensors, vol. 24, no. 7, Art. 2122, 2024, doi: 10.3390/s24072122.
[8]A. Hozouri, A. Mirzaei, and M. Effatparvar, “A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges,” Discover Artificial Intelligence, vol. 5, Art. 314, 2025, doi: 10.1007/s44163-025-00578-1.
[9]Y. Fu et al., “An Automata Based Intrusion Detection Method for Internet of Things,” Mobile Information Systems, 2017.
[10] ADDIN ZOTERO_BIBL {"uncited":[],"omitted":[],"custom":[]} CSL_BIBLIOGRAPHY M. Pawlicki, A. Pawlicka, R. Kozik, and M. ChoraĆ, “The survey on the dual nature of xAI challenges in intrusion detection and their potential for AI innovation,” Artificial Intelligence Review, vol. 57, Art. 330, 2024, doi: 10.1007/s10462-024-10972-3.
[11]Y. Zhang, R. C. Muniyandi, and F. Qamar, “A Review of Deep Learning Applications in Intrusion Detection Systems: Overcoming Challenges in Spatiotemporal Feature Extraction and Data Imbalance,” Applied Sciences, vol. 15, no. 3, Art. 1552, 2025, doi: 10.3390/app15031552.
[12]R. Chinnasamy, M. Subramanian, S. V. Easwaramoorthy, and J. Cho, “Deep learning-driven methods for network-based intrusion detection systems: A systematic review,” ICT Express, vol. 11, no. 1, pp. 181–215, 2025, doi: 10.1016/j.icte.2025.01.005.
[13]C. E. Shannon, “A Mathematical Theory of Communication,” Bell System Technical Journal, vol. 27, no. 3, pp. 379–423, 1948. doi: 10.1002/j.1538-7305.1948.tb01338.x.
[14]T. Maruf, "Hazard recognition system based on violation of the integrity of the field and changes in the intensity of illumination on the video image," 2022 International Conference on Information Science and Communications Technologies (ICISCT), Tashkent, Uzbekistan, 2022, pp. 1-3, doi: 10.1109/ICISCT55600.2022.10146933.
[15]L. Breiman, “Random Forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001. doi: 10.1023/A:1010933404324.
[16]J. Han, M. Kamber, and J. Pei, Data Mining: Concepts and Techniques, 3rd ed. Morgan Kaufmann, 2011. doi: 10.1016/C2009-0-61819-5.
[17]W. Lee and S. J. Stolfo, “A Framework for Constructing Features and Models for Intrusion Detection Systems,” ACM Transactions on Information and System Security, vol. 3, no. 4, pp. 227–261, 2000. doi: 10.1145/382912.382914.
[18]M. Tavallaee et al., “A Detailed Analysis of the KDD CUP 99 Data Set,” in IEEE Symposium on Computational Intelligence for Security and Defense Applications, 2009. doi: 10.1109/CISDA.2009.5356528.
[19]Maruf R.Tojiyev, Sanjar S. Kenjaev, Rashid Nasimov, Oybek D.Primkulov and Gulnoza K.Ernazarova, "Quantum computing algorithm for optimizing query distribution based on multi-criteria parameters in information systems," 2025 ICFNDS, in press.