DOI: 10.3390/info17090922 ISSN: 2078-2489

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

Zeyneb Berkat, Amina Fatima Zahra Yahiaoui, Mahfoud Aliouat, Emad Abd-Elrady, Aymen Bendjebbas, Kamel Eddine Haouari, Riyadh Bouddou

Class imbalance severely limits Network Intrusion Detection Systems (NIDSs) for minority Web attack classes: CICIDS2017 contains only 21 SQL Injection instances among 2.27 million benign flows. This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space. An anti-data-leakage protocol (stratified partitioning, post-split normalization, five-fold cross-validation, and a SHA-1 cryptographic membership audit of an 8881 –flow test sub-sample) found no hash collisions between this sub-sample and the evaluation partitions. The framework added 32,670 authentic flows, increasing SQL Injection from 21 to 10,678, XSS from 652 to 13,212, and WBF from 1507 to 10,960. Among four evaluated ensemble models, LightGBM performed best, achieving 99.85% Accuracy, 99.85% F1-score, 99.29% Balanced Accuracy, and 97.87 ± 1.88% in five-fold cross-validation, improving detection rates by 44.9% (XSS), 23.0% (WBF), and 16.6% (SQL Injection) over the original dataset. A volume-matched ablation study showed comparable aggregate accuracy to synthetic balancing methods (SMOTE, SMOTE-Tomek), while geometric diversity analysis confirmed that authentic traffic occupies feature-space regions unreachable by interpolation, and chronological holdout evaluation confirmed generalization to unseen traffic (F1: 98.53–99.90%). Real-traffic enrichment thus offers a practical, more realistic complement to synthetic balancing for minority Web-attack detection.