Absolom OriangaMark Travis LufeneAllan Kagimu Ssebatta2026-08-242026-08-242026-05-25https://hdl.handle.net/20.500.12311/3565UndergraduateCybersecurity remains a critical challenge for Small and Medium Enterprises (SMEs) in Uganda, where cybercrime increased by approximately 93.5% in 2024, causing losses of approximately UGX 72 billion. Approximately 40% of Ugandan SMEs have experienced cyberattacks, yet most continue to rely on basic signature-based tools that are incapable of detecting sophisticated or zero-day attacks. This project presents Vanguard-NIDS, a hybrid machine learning-based Network Intrusion Detection System designed for real-time intrusion monitoring in SME environments. The system captures live network packets using Scapy, extracts flow-level and statistical traffic features, and analyses them through a three-pronged detection pipeline comprising signature-based pattern matching, supervised machine learning via an ensemble of Random Forest, SVM, XGBoost, and LightGBM classifiers, and unsupervised anomaly detection via Isolation Forest, One-Class SVM, and Autoencoder models. A result fusion engine combines these predictions into a unified threat score. Models were trained and validated on the CICIDS2017, NSL-KDD, and UNSW-NB15 benchmark datasets. The Random Forest classifier achieved approximately 95% detection accuracy with a false positive rate of approximately 3%. A real-time React-based dashboard delivers live traffic monitoring, alert management, and system metrics via WebSocket communication, with an average end-to-end detection latency of under 25 milliseconds.enA hybrid machine learning network intrusion detection system for Small and Medium Enterprises (SMEs)Dissertation