Innovation science and technologiy Том 2 № 7 (2026) · с. 246-255
IMPROVING METHODS FOR DETECTING AND PREVENTING CYBERATTACKS IN COMPUTER NETWORKS
Babakulov, Bekzod
Аннотация
This study develops an adaptive hybrid framework for detecting and preventing cyberattacks in computernetworks. The framework combines signature matching, supervised classification, unsupervised anomaly detection, behavioralcorrelation, asset context, and a safeguarded response policy. Its purpose is to preserve reliable detection when legitimate trafficchanges and when previously unseen attacks do not match existing rules. A design-science methodology was used together witha controlled streaming emulation containing 120,000 training flows and 120,000 test flows distributed across baseline, benigndrift,and mixed zero-day-like windows. In the emulation, the proposed method achieved 98.94% accuracy, 98.31% precision,97.39% recall, a 97.85% F1-score, and a 0.55% false-positive rate. The strongest advantage appeared in the mixed/zero-daywindow, where its F1-score reached 94.83%, compared with 73.90% for a static Random Forest and 57.26% for signature-onlydetection. The results support a practical conclusion: prevention should be separated from detection and activated graduallythrough logging, alerting, rate limiting, session interruption, and isolation, with higher-impact actions requiring corroborationand rollback.
network intrusion detection; intrusion prevention; concept drift; Random Forest; Isolation Forest; behavioral analytics; zero-day attack; adaptive threshold; cyber resilience
Источник метаданных: OAI-PMH архив журнала · Sindex не хранит полный текст, а даёт ссылку на источник.