Hybrid Machine Learning Based Integrated Network Scanning And Anomaly Framework

30 Jul

Authors: Sarthak Jain, Suyash, Upendra Kumar, Utsav Chauhan, Ashish Kumar

Abstract: Modern networks produced enormous volumes of data which made them increasingly vulnerable to advanced cyber threats. Traditional scanning tools and standalone anomaly detection systems fell short in identifying evolving or zero day attacks. This study proposed a hybrid framework that integrated active network scanning with machine learning based anomaly detection to deliver an adaptive and automated solution. The framework combined Nmap based host scanning tcpdump based traffic capture and Zeek based feature extraction with a Random Forest classifier and an autoencoder trained on normal traffic to flag deviations. Recent advancements in supervised and unsupervised anomaly detection together with integrated intrusion detection systems published between 2020 and 2025 were reviewed and synthesized to position the proposed approach within the broader field. Experimental comparison across five learning models showed that the Convolutional Neural Network achieved the highest accuracy of 93 percent followed by Long Short Term Memory at 91 percent while Random Forest balanced accuracy and interpretability at 89 percent. The hybrid correlation mechanism that combined scan derived signals with model predictions reduced false alarms and strengthened real time threat visibility compared with single method systems. The study concluded that combining active scanning with machine learning significantly improved detection accuracy reduced false positives and enabled actionable reporting for security analysts. Future directions identified included adaptive learning methods lightweight models suited for edge devices and secure distributed detection through federated learning.

DOI: http://doi.org/10.5281/zenodo.21701384