Abstract
Advanced Persistent Threats (APTs) remain among the most damaging risks to enterprise networks: they evade signature-based defenses, persist inside compromised environments, and cause substantial harm. Most machine learning approaches to intrusion detection treat the problem as binary classification and therefore offer little support for the risk prioritisation that Security Operations Centre (SOC) analysts actually require. This paper presents an Intrusion Detection System (IDS)-contextual ensemble learning framework that assigns network traffic to three operationally meaningful risk tiers: High, Medium and Low. Sixteen domain-knowledge engineered features are combined with IDS-generated contextual annotations, raw behavioural flow measurements and temporal components to form a 36-dimensional input representation. A one-way analysis of variance (ANOVA) with eta-squared effect sizing, performed before any model is trained, shows that none of the nine raw behavioural features carries meaningful discriminating power for risk-tier assignment, which establishes the need for IDS context. Five classifiers are evaluated on a balanced dataset of 125,000 APT flow records. Extra Trees performs best, reaching 89.35% accuracy, a Macro F1 of 0.8941, a Matthews Correlation Coefficient of 0.8404 and a macro Area Under the Curve (AUC) of 0.9829, at an inference cost of approximately 42 microseconds per record. A six-configuration ablation study shows that removing the IDS annotation alone reduces Macro F1 from 0.8941 to 0.3341, the chance level for three balanced classes. Robustness is confirmed by five-fold stratified cross-validation and by a fairness audit across the four network protocol types present in the data.References
- Hutchins, Eric M., Michael J. Cloppert, and Rohan M. Amin. "Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains." Leading Issues in Information Warfare & Security Research 1, no. 1 (2011): 80.
- IBM Security. (2024). Cost of a Data Breach Report 2024. IBM Corporation.
- CrowdStrike. (2024). 2024 CrowdStrike Global Threat Report. CrowdStrike Holdings.
- MITRE. (2024). MITRE ATT&CK: Adversarial Tactics, Techniques, and Common Knowledge (v15.0). https://attack.mitre.org/
- Alshamrani, Adel, Sowmya Myneni, Ankur Chowdhary, and Dijiang Huang. "A Survey on Advanced Persistent Threats: Techniques, Solutions, Challenges, and Research Opportunities." IEEE Communications Surveys & Tutorials 21, no. 2 (2019): 1851-1877.
- Milajerdi, Sadegh M., Rigel Gjomemo, Birhanu Eshete, Ramachandran Sekar, and V. N. Venkatakrishnan. "Holmes: Real-Time Apt Detection Through Correlation of Suspicious Information Flows." In 2019 IEEE symposium on security and privacy (SP), IEEE, 2019, 1137-1152.
- Nguyen, Thien Duc, Samuel Marchal, Markus Miettinen, Hossein Fereidooni, Nadarajah Asokan, and Ahmad-Reza Sadeghi. "DÏoT: A Federated Self-Learning Anomaly Detection System for IoT." In 2019 IEEE 39th International conference on distributed computing systems (ICDCS), IEEE, 2019, 756-767.
- Khraisat, Ansam, Iqbal Gondal, Peter Vamplew, and Joarder Kamruzzaman. "Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges." Cybersecurity 2, no. 1 (2019): 1-22.
- Sharafaldin, Iman, Arash Habibi Lashkari, and Ali A. Ghorbani. "Toward Generating A New Intrusion Detection Dataset and Intrusion Traffic Characterization." ICISSp 1, no. 2018 (2018): 108-116.
- Imrana, Yakubu, Yanping Xiang, Liaqat Ali, and Zaharawu Abdul-Rauf. "A bidirectional LSTM deep learning approach for intrusion detection." Expert Systems with Applications 185 (2021): 115524.
- Lo, Wai Weng, Siamak Layeghy, Mohanad Sarhan, Marcus Gallagher, and Marius Portmann. "E-graphsage: A Graph Neural Network Based Intrusion Detection System for IoT." In NOMS 2022-2022 IEEE/iFIP network operations and management symposium, IEEE, 2022, 1-9.
- Xi, Chiming, Hui Wang, and Xubin Wang. "A Novel Multi-Scale Network Intrusion Detection Model with Transformer." Scientific Reports 14, no. 1 (2024): 23239.
- Wu, Zihan, Hong Zhang, Penghai Wang, and Zhibo Sun. "RTIDS: A Robust Transformer-Based Approach for Intrusion Detection System." IEEE access 10 (2022): 64375-64387.
- Kasongo, Sydney M., and Yanxia Sun. "Performance Analysis of Intrusion Detection Systems Using a Feature Selection Method on the UNSW-NB15 Dataset." Journal of Big Data 7, no. 1 (2020): 105.
- Mell, Peter, Karen Scarfone, and Sasha Romanosky. "A complete guide to the common vulnerability scoring system version 2.0." In Published by FIRST-forum of incident response and security teams, vol. 1, 2007, 23.
- Mahbooba, Basim, Mohan Timilsina, Radhya Sahal, and Martin Serrano. "Explainable Artificial Intelligence (XAI) to Enhance Trust Management in Intrusion Detection Systems Using Decision Tree Model." Complexity 2021, no. 1 (2021): 6634811.
- Jalalvand, Fatemeh, Mohan Baruwal Chhetri, Surya Nepal, and Cecile Paris. "Alert Prioritisation in Security Operations Centres: A Systematic Survey on Criteria and Methods." ACM Computing Surveys 57, no. 2 (2024): 1-36.
- Moustafa, Nour, and Jill Slay. "UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set)." In 2015 military communications and information systems conference (MilCIS), IEEE, 2015, 1-6.
- Cohen, J. (1988). Statistical Power Analysis for the Behavioral Sciences (2nd ed.). Lawrence Erlbaum Associates.
- National Institute of Standards and Technology. (2024). SP 800-61r3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management. NIST.
- MITRE. (2024). MITRE ATT&CK tactic-level severity reference (v15.0). https://attack.mitre.org/tactics/
- Roesch, Martin. "Snort: Lightweight Intrusion Detection for Networks." In Lisa, vol. 99, no. 1, 1999, 229-238.
- Open Information Security Foundation. (2024). Suricata Open Source IDS/IPS (v7.0). https://suricata.io/
- Geurts, Pierre, Damien Ernst, and Louis Wehenkel. "Extremely randomized trees." Machine learning 63, no. 1 (2006): 3-42.
- Lundberg, Scott M., and Su-In Lee. "A Unified Approach to Interpreting Model Predictions." Advances in neural information processing systems 30 (2017).

Journal of Trends in Computer Science and Smart Technology