Real-Time Port Scanning Attack Detection Using Adaptive Entropy Analysis and Random Forest-based Hybrid Model
Журнал: International Journal of Wireless and Microwave Technologies @ijwmt
Статья в выпуске: 5 Vol.16, 2026 года.
Бесплатный доступ
Network port scanning represents a critical reconnaissance phase preceding advanced cyber attacks and poses a significant threat to modern network infrastructures. Conventional signature-based detection systems and static threshold mechanisms are often ineffective in detecting stealthy and low-rate scanning activities in dynamic network environments. This paper proposes a hybrid intrusion detection approach that combines adaptive entropy-based filtering with a Random Forest classifier. The proposed method employs a sliding window mechanism to dynamically adjust detection thresholds based on statistical properties of network traffic, thereby improving adaptability under varying load conditions. Experimental evaluation conducted on the CIC-IDS2017 dataset demonstrates that the proposed model achieves a classification accuracy of 98.7% with a False Positive Rate (FPR) of 1.8%, outperforming both standalone entropy-based and machine learning-based approaches. In addition, the model maintains an average processing latency of 2.3 ms per packet, confirming its suitability for real-time deployment in high-speed network environments. The results indicate that the proposed hybrid approach effectively improves detection performance while maintaining low computational overhead, making it a practical solution for modern intrusion detection systems. However, the proposed approach has certain limitations, including reliance on traffic metadata and reduced effectiveness in encrypted environments.
Короткий адрес: https://sciup.org/15020814
IDS: 15020814 | DOI: 10.5815/ijwmt.2026.05.25