A hybrid machine learning network intrusion detection system for Small and Medium Enterprises (SMEs)
| dc.contributor.author | Absolom Orianga | |
| dc.contributor.author | Mark Travis Lufene | |
| dc.contributor.author | Allan Kagimu Ssebatta | |
| dc.date.accessioned | 2026-08-24T08:04:19Z | |
| dc.date.available | 2026-08-24T08:04:19Z | |
| dc.date.issued | 2026-05-25 | |
| dc.description | Undergraduate | |
| dc.description.abstract | Cybersecurity remains a critical challenge for Small and Medium Enterprises (SMEs) in Uganda, where cybercrime increased by approximately 93.5% in 2024, causing losses of approximately UGX 72 billion. Approximately 40% of Ugandan SMEs have experienced cyberattacks, yet most continue to rely on basic signature-based tools that are incapable of detecting sophisticated or zero-day attacks. This project presents Vanguard-NIDS, a hybrid machine learning-based Network Intrusion Detection System designed for real-time intrusion monitoring in SME environments. The system captures live network packets using Scapy, extracts flow-level and statistical traffic features, and analyses them through a three-pronged detection pipeline comprising signature-based pattern matching, supervised machine learning via an ensemble of Random Forest, SVM, XGBoost, and LightGBM classifiers, and unsupervised anomaly detection via Isolation Forest, One-Class SVM, and Autoencoder models. A result fusion engine combines these predictions into a unified threat score. Models were trained and validated on the CICIDS2017, NSL-KDD, and UNSW-NB15 benchmark datasets. The Random Forest classifier achieved approximately 95% detection accuracy with a false positive rate of approximately 3%. A real-time React-based dashboard delivers live traffic monitoring, alert management, and system metrics via WebSocket communication, with an average end-to-end detection latency of under 25 milliseconds. | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12311/3565 | |
| dc.language.iso | en | |
| dc.publisher | Uganda Christian University | |
| dc.title | A hybrid machine learning network intrusion detection system for Small and Medium Enterprises (SMEs) | |
| dc.type | Dissertation |