Ensemble-Based Multi-Engine Intrusion Detection: Integrating Signature, Anomaly, and Deep Learning Approaches for Enhanced Cybersecurity
Main Article Content
Abstract
The increasing sophistication of cyber threats requires intrusion detection systems capable of identifying diverse attack vectors through multiple detection paradigms. Single-methodology approaches, whether signature-based, anomaly-based, or machine learning-based, exhibit inherent limitations that compromise their effectiveness against evolving threats. This paper proposes a comprehensive ensemble-based intrusion detection system that synergistically integrates four complementary detection engines: signature-based pattern matching, statistical anomaly detection, One-Class Support Vector Machines, and deep learning using Convolutional Neural Networks with Long Short-Term Memory networks. The ensemble architecture employs an intelligent fusion mechanism that combines heterogeneous detection outputs through optimized weighted averaging, leveraging the complementary error profiles of individual engines to achieve superior overall performance. We extract 78 network flow features spanning temporal, statistical, protocol-specific, and behavioral dimensions, applying feature selection algorithms to identify optimal subsets balancing detection accuracy with computational efficiency. Extensive evaluation on NSL-KDD, CICIDS2017, and UNSW-NB15 benchmark datasets demonstrates that the proposed ensemble achieves 97.14% accuracy with 2.52% false positive rate on NSL-KDD, representing 40-55% reduction in false positives compared to pure anomaly-based systems whilst maintaining 18-25% higher detection rates than signature-only approaches. The ensemble demonstrates robust generalization across datasets, achieving 83.58% accuracy when trained on NSL-KDD and tested on UNSW-NB15 without retraining, outperforming single-engine baselines by 5.24%. Ablation studies quantify individual engine contributions, revealing that signature detection provides high-precision identification of known threats, statistical anomaly detection captures deviations from baseline behaviors, and deep learning identifies complex attack patterns including novel zero-day exploits. The ensemble fusion mechanism reduces detection latency to 0.42ms at 95th percentile, enabling deployment on high-speed networks processing 100+ Gbps traffic.