NAD-CD: Addressing concept drift in network IDS alert classification for Security Operations Centers

A Network Intrusion Detection System (network IDS or NIDS) is a widely used technology to enhance an organization’s security posture. A NIDS monitors the organizational network for cyber attacks, malware activity, and other malicious network traffic, raising alerts upon detecting such traffic. Unfortunately, NIDS technologies are known to generate large numbers of alerts daily, which can overwhelm security analysts in Security Operations Centers (SOCs). To address this, Machine Learning (ML)-based NIDS alert classification methods have been proposed in the research literature. However, previous works have not addressed the issue of concept drift in NIDS alert data. In addition, most previous works have not shared the NIDS alert datasets, and publicly available datasets are not well suited for concept drift-related research. This paper addresses these shortcomings by introducing the NIDS Alert Data with Concept Drift (NAD-CD) dataset, which spans 1.5 years and focuses on the concept drift issue. Furthermore, the paper examines passive supervised and semi-supervised ML strategies to mitigate concept drift. Finally, it demonstrates that active learning-based semi-supervised ML is an efficient solution for handling concept drift, significantly reducing the labeling workload of security analysts in SOC environments. For the sake of reproducibility, we make the NAD-CD dataset and experimental code publicly available at https://github.com/ristov/nad-cd .

Authors

Institutions

Publication Details

Journal
Journal of Information Security and Applications
Published
2026-10-06
DOI
https://doi.org/10.1016/j.jisa.2026.104663
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

NAD-CD: Addressing concept drift in network IDS alert classification for Security Operations Centers

Alejandro Guerra-Manzanares, Risto Vaarandi
Journal of Information Security and Applications
Network Security and Intrusion Detection
article

NAD-CD: Addressing concept drift in network IDS alert classification for Security Operations Centers

Alejandro Guerra-Manzanares, Risto Vaarandi
article en

Abstract

A Network Intrusion Detection System (network IDS or NIDS) is a widely used technology to enhance an organization’s security posture. A NIDS monitors the organizational network for cyber attacks, malware activity, and other malicious network traffic, raising alerts upon detecting such traffic. Unfortunately, NIDS technologies are known to generate large numbers of alerts daily, which can overwhelm security analysts in Security Operations Centers (SOCs). To address this, Machine Learning (ML)-based NIDS alert classification methods have been proposed in the research literature. However, previous works have not addressed the issue of concept drift in NIDS alert data. In addition, most previous works have not shared the NIDS alert datasets, and publicly available datasets are not well suited for concept drift-related research. This paper addresses these shortcomings by introducing the NIDS Alert Data with Concept Drift (NAD-CD) dataset, which spans 1.5 years and focuses on the concept drift issue. Furthermore, the paper examines passive supervised and semi-supervised ML strategies to mitigate concept drift. Finally, it demonstrates that active learning-based semi-supervised ML is an efficient solution for handling concept drift, significantly reducing the labeling workload of security analysts in SOC environments. For the sake of reproducibility, we make the NAD-CD dataset and experimental code publicly available at https://github.com/ristov/nad-cd .

Journal of Information Security and ApplicationsVol. 103
Tallinn University of Technology (EE), University of Nottingham Ningbo China (CN)
Openalex Percentile: Top 11%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

NAD-CD: Addressing concept drift in network IDS alert classification for Security Operations Centers — Alejandro Guerra-Manzanares, Risto Vaarandi · Journal of Information Security and Applications (2026) | TGRS Research Map | TGRS