Real Time Intrusion Detection System Based on Web Log File Analysis
Abdalla, Rawand Raouf, Jumaa, Alaa Khalil, and Fadhil, Ahmad Freidoon (2025) Real Time Intrusion Detection System Based on Web Log File Analysis. Kurdistan Journal of Applied Research, 10 (1). pp. 35-49.
|
PDF (Published Version)
- Published Version
Available under License Creative Commons Attribution Non-commercial No Derivatives. Download (790kB) | Preview |
Abstract
Web log data have a wealth of useful data about a website. They contain the history of all users’ activities while accessing websites. Some log files contain records of various intrusion types that refer to unauthorized or malicious activities recorded during website access. System and network logs are examined as part of log file analysis for Intrusion Detection Systems (IDS) to identify suspicious activities and possible security risks. Many existing IDS systems suffer from false positives and false negatives, which can either fail to identify real dangers or overwhelm administrators with unnecessary alarms. Real-time cyberattacks are common, and any delay in detection can lead to serious consequences like data breaches and system outages. In this paper, we developed a real time IDS based on weblog analysis which is used to predict if the user’s request is an attack, normal, or suspicious. This can be done by utilizing the con-tents of the Apache access log data, considering some of the hyper text transfer protocol request features obtained by analyzing the user’s requests. In this work, various data preprocessing techniques are applied, and key features are extracted, enhancing the system's ability to effectively detect intrusions. The model was constructed using four machine learning algorithms: gradient-boosted trees, decision tree, random forest, and support vector machine. According to the results obtained, the proposed model with the random forest algorithm produces the most accurate model among the others. It attained 99.66% precision, 99.66% recall, and 99.83% accuracy score.
| Item ID: | 89242 |
|---|---|
| Item Type: | Article (Research - C1) |
| ISSN: | 2411-7706 |
| Keywords: | Feature engineering, Intrusion detection system Real time system, Web log file, Web usage analysis |
| Copyright Information: | © 2025 by the authors. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY-NC-ND 4.0) |
| Date Deposited: | 17 Jul 2026 02:13 |
| FoR Codes: | 46 INFORMATION AND COMPUTING SCIENCES > 4604 Cybersecurity and privacy > 460403 Data security and protection @ 100% |
| SEO Codes: | 22 INFORMATION AND COMMUNICATION SERVICES > 2204 Information systems, technologies and services > 220405 Cybersecurity @ 100% |
| More Statistics |
