Asosiy kontentga oʻtish
AkademIndex

Mahsulotlar

Ishlab chiquvchilar uchun

AkademBasetez oradaEkotizim uchun ochiq API
Lotin
Oʻzbek
Maqola

A Lightweight Cascade-Based Farmework for Real-Time Zero-Day Attack Detection

Alpamis KutlimuratovDepartment of Applied Informatics, Kimyo International University in Tashkent, Tashkent 100121, UzbekistanFurkat RakhmatovDepartment of Programming Technologies, Tashkent University of Information Technologies Named After Muhammad al-Khwarizmi, Tashkent 100084, UzbekistanJamshid KhamzaevDepartment of Computer Systems, Tashkent University of Information Technologies Named After Muhammad al-Khwarizmi, Tashkent 100084, UzbekistanIslambek SaymanovApplied Mathematics and Intelligent Technologies Faculty, National University of Uzbekistan, Tashkent 100174, UzbekistanPiratdin AllayarovDepartment of Econometrics, Tashkent State University of Economics, Tashkent 100066, UzbekistanGamzatdin BekbaevDepartment of Finance and Digital Economy, Tashkent State University of Economics, Tashkent 100066, UzbekistanShаvkаt ОtаmurоdоvDepartment of Economics, Termez University of Economics and Service, Termez 190111, UzbekistanFazliddin MakhmudovDepartment of Computer Engineering, Gachon University, Seongnam 13120, Republic of Korea
Computersjournal2026en
ABI

Annotatsiya

Zero-day intrusion detection is still a difficult task because of the difference between high laboratory precision and real-time deployability under strict operational constraints. This paper proposes a lightweight two-stage cascade architecture that is specifically designed for CPU-only environments and strict zero-day evaluation. The proposed architecture only uses statistical and flow-level metadata attributes, which are independent of payload analysis, to ensure compatibility with encrypted traffic. The first stage of the proposed architecture is precision oriented to detect potentially malicious traffic with a low decision threshold, and the second stage is precision oriented to enhance classification and remove false positives. To avoid optimistic bias, a strict attack-type separation protocol is employed, where testing attack types are strictly prohibited from training. The proposed method is tested on three benchmark datasets: CSIC 2012 (HTTP level), UNSW-NB15 (intra-domain), and CSE-CIC-IDS2018 (cross-domain). The experimental results show the excellent intra-domain zero-day detection capability (up to 94.81% accuracy with 0.50% FPR), controllable performance degradation in the cross-domain setting (80.53% accuracy with near-zero FPR), and extremely low FP rates on all datasets. The system provides microsecond-level inference latency (0.002–0.006 ms), a throughput of up to 470,000 requests per second, and memory usage below 6.2 MB without GPU support. These results confirm the significance of architectural optimization and thorough evaluation in building efficient zero-day detection systems.

Mavzular

Identifikatorlar

Iqtiboslar va manbalar

0 ta iqtibos0 ta foydalanilgan manba
Koʻrsatkichlar — AkademScholar · Tez orada