AI-Powered Zero-Day Malware Detection Using Network Traffic Analysis

Traditional Network Intrusion Detection Systems (NIDS) primarily depend on signature-based matching paradigms, which natively fail when confronted with highly customized, polymorphic, or entirely novel zero-day malware threats. To address this structural vulnerability, this paper introduces a robust Machine Learning-driven NIDS framework optimized for zero-day threat identification via behavioral network traffic analysis. Leveraging an advanced Random Forest ensemble classifier, the proposed system learns the mathematical operational boundaries of normal network communication to flag anomalous, malicious deviations. The model was trained and validated on a high-dimensional cybersecurity dataset containing diverse threat vectors such as Distributed Denial of Service (DDoS) and Brute Force attacks. Comprehensive feature engineering was conducted to extract 15 critical statistical traffic indicators, including packet size variations and flow velocities. Experimental evaluations demonstrate that the Random Forest algorithm achieves superior performance, securing both training and testing accuracies exceeding 99% while maintaining exceptionally high precision and low false-positive rates. To facilitate practical enterprise deployment without introducing endpoint latency, a distributed, decoupled cloud-based architecture is proposed. This design routes lightweight endpoint data extraction scripts to a centralized cloud analytics engine, ensuring real-time threat detection and scalable computational processing.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-17
DOI
https://doi.org/10.5281/zenodo.22816123
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

AI-Powered Zero-Day Malware Detection Using Network Traffic Analysis

M.P. VIJAYKUMAR, RUTUJA VIDYADHAR PATIL
Zenodo (CERN European Organization for Nuclear Research)
Network Security and Intrusion Detection
article

AI-Powered Zero-Day Malware Detection Using Network Traffic Analysis

M.P. VIJAYKUMAR, RUTUJA VIDYADHAR PATIL
article en

Abstract

Traditional Network Intrusion Detection Systems (NIDS) primarily depend on signature-based matching paradigms, which natively fail when confronted with highly customized, polymorphic, or entirely novel zero-day malware threats. To address this structural vulnerability, this paper introduces a robust Machine Learning-driven NIDS framework optimized for zero-day threat identification via behavioral network traffic analysis. Leveraging an advanced Random Forest ensemble classifier, the proposed system learns the mathematical operational boundaries of normal network communication to flag anomalous, malicious deviations. The model was trained and validated on a high-dimensional cybersecurity dataset containing diverse threat vectors such as Distributed Denial of Service (DDoS) and Brute Force attacks. Comprehensive feature engineering was conducted to extract 15 critical statistical traffic indicators, including packet size variations and flow velocities. Experimental evaluations demonstrate that the Random Forest algorithm achieves superior performance, securing both training and testing accuracies exceeding 99% while maintaining exceptionally high precision and low false-positive rates. To facilitate practical enterprise deployment without introducing endpoint latency, a distributed, decoupled cloud-based architecture is proposed. This design routes lightweight endpoint data extraction scripts to a centralized cloud analytics engine, ensuring real-time threat detection and scalable computational processing.

Zenodo (CERN European Organization for Nuclear Research)
Life in Land
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

AI-Powered Zero-Day Malware Detection Using Network Traffic Analysis — M.P. VIJAYKUMAR, RUTUJA VIDYADHAR PATIL · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS