Machine learning network intrusion detection systems (IDS) rely on aggregate flow statistics that discard distributional structure, while established entropy measures require raw packet sequences unavailable in pre-aggregated flow datasets. We propose Multi-Level Distributional Entropy (MDE), an analytical framework that derives interpretable entropy features directly from flow-level summary statistics at three levels: within-flow Gaussian differential entropy, cross-directional Jensen-Shannon divergence (JSD), and Transmission Control Protocol (TCP) flag-pattern Shannon entropy, without raw packet access or training data.
arXiv:2609.05701v1 Announce Type: cross
Abstract: One of the biggest risks faced by Software Defined Networks (SDN) is the Distributed Denial of Service (DDoS) attack in which a compromised controlle...
By Adeel Ahmad, Ali Akarma, Ahmad Ali, Hammad Muneer, Toqeer Ali Syed
arXiv:2607. 15379v1 Announce Type: cross Abstract: Network anomaly detection is increasingly challenging due to the growing diversity and variability of traffic patterns, which are not always well captured by traditional statistical features.
By Iuri Mundstock, Abreu Quevedo, J\'eferson Campos Nobre, Roben C. Lunardi, Thiago L. T. da Silveira, Bruno L. Dalmazo
arXiv:2607. 13203v1 Announce Type: cross Abstract: False alarms remain a major barrier to deploying network intrusion detection systems (NIDS).
By Abu Fuad Ahmad, Istiaque Ahmed
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
JEV-IDS is an open experimental general network intrusion detection system that uses the Jev System One Model to detect zero‑day intrusions even when labeled data are scarce. The system processes one flow per request and asks the model two questions: a binary attack probability and a finite‑choice traffic category. In tests on a 300‑flow NSL‑KDD pilot split, JEV-IDS achieved an F1‑score of 0.859, precision of 0.941, recall of 0.790, and a novel‑attack recall of 0.838, while being 4.8 times faster and 3.8 times cheaper than GPT‑5.6 Luna and producing 15 times fewer false alarms than a low‑data Random Forest.
By Paulo Severo, Silvio E. Quincozes, Amanda Dias