📖 ABSTRACT/OVERVIEW
University networks in Nigeria are increasingly targeted by cyberattacks including DDoS, phishing-based credential theft, and ransomware, yet empirical evaluation of intrusion detection system performance under Nigerian network traffic conditions is absent from the research literature. This study analytically evaluates the performance of signature-based and anomaly-based intrusion detection systems under Nigerian university network traffic profiles. A testbed was constructed replicating the network architecture of a federal university in North Central Nigeria, using Mininet network emulation and traffic traces captured from actual university edge routers over 30 days. Snort (signature-based IDS) and an isolation forest-based anomaly detection model (Python/scikit-learn) were deployed and compared. Traffic injection of 12 attack categories from the NSL-KDD and CICIDS 2017 datasets supplemented real traffic. Evaluation used detection rate, false positive rate, processing latency, and resource overhead. Snort achieved a detection rate of 91.4 percent but a false positive rate of 14.3 percent, with latency increasing sharply under traffic loads above 200 Mbps. The anomaly detection model achieved 87.2 percent detection rate and 8.6 percent false positive rate at all traffic levels. A hybrid ensemble combining both systems achieved 94.1 percent detection rate and 7.2 percent false positive rate at acceptable overhead. The study fills an empirical gap in IDS evaluation research for sub-Saharan African network environments and recommends the hybrid ensemble approach for university network security deployment in Nigeria.
Keywords: intrusion detection system, university network, cybersecurity, anomaly detection, Nigeria
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬