Traditional Network Intrusion Detection Systems (NIDS) primarily depend on signature-based matching paradigms, which natively fail when confronted with highly customized, polymorphic, or entirely novel zero-day malware threats. To address this structural vulnerability, this paper introduces a robust Machine Learning-driven NIDS framework optimized for zero-day threat identification via behavioral network traffic analysis. Leveraging an advanced Random Forest ensemble classifier, the proposed system learns the mathematical operational boundaries of normal network communication to flag anomalous, malicious deviations. The model was trained and validated on a high-dimensional cybersecurity dataset containing diverse threat vectors such as Distributed Denial of Service (DDoS) and Brute Force attacks. Comprehensive feature engineering was conducted to extract 15 critical statistical traffic indicators, including packet size variations and flow velocities. Experimental evaluations demonstrate that the Random Forest algorithm achieves superior performance, securing both training and testing accuracies exceeding 99% while maintaining exceptionally high precision and low false-positive rates. To facilitate practical enterprise deployment without introducing endpoint latency, a distributed, decoupled cloud-based architecture is proposed. This design routes lightweight endpoint data extraction scripts to a centralized cloud analytics engine, ensuring real-time threat detection and scalable computational processing.
Relying on legacy signature databases is insufficient for securing modern digital infrastructures against sophisticated zero-day exploits. This paper successfully developed an AI powered Network Intrusion Detection System that achieves a behavioural classification accuracy exceeding 99% using an optimized Random Forest algorithm. By coupling this high accuracy classifier with a distributed cloud architecture, the framework ensures enterprise endpoints remain computational unburdened, delegating heavy analytical tasks to a high capacity cloud manager.
References
[1] H. Hindy, D. Brosset, M. Bures, et al., "Machine Learning for Zero-Day Malware Detection: A Survey on Challenges and Future Directions," IEEE Access, vol. 9, pp. 43452–43472, 2021, doi: 10.1109/ACCESS.2021.3066523. [2] Y. Gao, H. Wu, B. Song, et al., "A Distributed Network Intrusion Detection System for DDoS Detection Based on Big Data Framework," IEEE Access, vol. 7, pp. 154560–154571, 2019, doi: 10.1109/ACCESS.2019.2948625. [3] Y. Zhang and X. Chen, "Research on Intrusion Detection Based on an Enhanced Random Forest Algorithm," Applied Sciences (MDPI), vol. 14, no. 2, p. 714, 2024, doi: 10.3390/app14020714. [4] Z. Ahmad, A. S. Shahid, P. Thulasiraman, et al., "Random Forest Classifier Based Network Intrusion Detection System," in Proceedings of the International Conference on Computer and Communication Systems (ICCCS), 2021, pp. 205–212, doi: 10.1109/ICCCS51487.2021.9449234. [5] V. Kumar and D. Sinha, "A Survey of Cloud Computing Detection Techniques against DDoS Attacks," Journal of Information Security, vol. 12, no. 1, pp. 44–62, 2021, doi: 10.4236/jis.2021.121003
📋 How to Cite This Paper
RUTUJA VIDYADHAR PATIL, M.P. VIJAYKUMAR (2026). AI-Powered Zero-Day Malware Detection Using Network Traffic Analysis. International Journal of Engineering and Techniques, 12(5), 218–222. ISSN: 2395-1303. DOI: https://doi.org/10.5281/zenodo.22816123