TY - GEN
T1 - Efficient Early Network Intrusion Detection based on Sub-Flow Segmentation
AU - Pei, Chonghao
AU - Mhamdi, Lotfi
AU - Almutairi, Ali F.
AU - Langar, Rami
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - With the increasing complexity of network traffic and the diversification of cyber attacks, traditional intrusion detection systems based on full-session analysis face challenges in real-time performance and computational efficiency. To enhance early detection capability, recent research has explored using only partial flows or the first few packets for rapid classification. The few proposed approaches rely mainly on time-driven flow segmentation, making it inefficient to capture the full flow context. This paper introduces a novel framework (named Hybrid Prefix N) that combines both time-based features as well as other crucial flow features (e.g., SYN/FIN/RST) to better capture flow contextual, bidirectional and boundary features. In particular, as we shall see, the flow segmentation strategy significantly affects feature distributions and model overall performance. The Experimental results show that although the time-driven approach achieves slightly higher numerical metrics, it suffers from class imbalance and high false positive rates. On the other hand, the proposed Hybrid segmentation model provided high accuracy while providing a more reliable and semantically consistent foundation for real-time intrusion detection.
AB - With the increasing complexity of network traffic and the diversification of cyber attacks, traditional intrusion detection systems based on full-session analysis face challenges in real-time performance and computational efficiency. To enhance early detection capability, recent research has explored using only partial flows or the first few packets for rapid classification. The few proposed approaches rely mainly on time-driven flow segmentation, making it inefficient to capture the full flow context. This paper introduces a novel framework (named Hybrid Prefix N) that combines both time-based features as well as other crucial flow features (e.g., SYN/FIN/RST) to better capture flow contextual, bidirectional and boundary features. In particular, as we shall see, the flow segmentation strategy significantly affects feature distributions and model overall performance. The Experimental results show that although the time-driven approach achieves slightly higher numerical metrics, it suffers from class imbalance and high false positive rates. On the other hand, the proposed Hybrid segmentation model provided high accuracy while providing a more reliable and semantically consistent foundation for real-time intrusion detection.
KW - Early Detection
KW - Flow Segmentation
KW - Intrusion Detection
KW - Network Security
KW - Random Forest
UR - https://www.scopus.com/pages/publications/105045364687
U2 - 10.1109/ICC59461.2026.11586853
DO - 10.1109/ICC59461.2026.11586853
M3 - Contribution to conference proceedings
AN - SCOPUS:105045364687
T3 - IEEE International Conference on Communications
BT - ICC 2026 - IEEE International Conference on Communications, Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2026 IEEE International Conference on Communications, ICC 2026
Y2 - 24 May 2026 through 28 May 2026
ER -