1 Department of Computer Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
2 Department of Civil Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
3 Department of Mechanical Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
4 Department of Chemical Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
5 Department of Biomedical Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
6 Department of Electrical and Electronic Engineering, Faculty of Engineering and the Built Environment, State University of Medical and Applied Sciences, Igbo-Eno, Enugu State, Nigeria.
* Corresponding Author
ORCID Details
Kingsley I. Chibueze: https://orcid.org/0009-0008-9387-0297
World Journal of Advanced Research and Reviews, 2026, 31(03), 980–988
Article DOI: 10.30574/wjarr.2026.31.3.2404
Received on 02 August 2026; revised on 13 September 2026; accepted on 15 September 2026
Network intrusion detection systems must identify known attacks while remaining sensitive to previously unseen or behaviorally unusual traffic. Single detection paradigms are limited because signature-based methods depend on known attack patterns, supervised classifiers may miss behavior outside their training distribution, and anomaly detectors may generate false alarms when legitimate traffic changes. This study presents an intelligent hybrid network intrusion detection system that combines signature-based detection, LightGBM supervised classification, and Isolation Forest anomaly detection in a sequential pipeline. The system was implemented as a Python/Flask application with passive packet monitoring and manual analysis of JSON/CSV traffic records. HIKARI-2021 was used for supervised training. The dataset contained 555,278 records; after preprocessing, 81 features were retained. A stratified 80:20 train-test split was used for LightGBM, while Isolation Forest was trained on 414,065 benign training records. LightGBM was configured with 250 estimators, a learning rate of 0.05, 48 leaves, class weighting, and a tuned decision threshold of 0.7987. On the test set, the classifier achieved 90.60% accuracy, 94.63% weighted precision, 90.60% weighted recall, and 92.01% weighted F1-score. The suspicious-class recall was 81.89%, while suspicious-class precision was 40.50%. The ROC curve produced an AUC of 0.9522. The results demonstrate that the supervised component provides useful discrimination, while the hybrid architecture supplies complementary signature and anomaly-detection mechanisms. Because the available experiment did not produce a separate end-to-end quantitative evaluation of the complete hybrid pipeline, the reported numerical metrics are explicitly attributed to the LightGBM component.
Hybrid Intrusion Detection; Network Intrusion Detection; Lightgbm; Isolation Forest; Signature-Based Detection; HIKARI-2021; SHAP; Explainable Artificial Intelligence.
Preview Article PDF
Kingsley I. Chibueze, C.O. Ugwoke, Emeka Augustine Chinachi, Malachy O. Ugwuoke and Onyeabo Uzoamaka Agatha. DESIGN AND IMPLEMENTATION OF AN INTELLIGENT HYBRID INTRUSION DETECTION SYSTEM USING SIGNATURE-BASED DETECTION, LIGHTGBM, AND ISOLATION FOREST. World Journal of Advanced Research and Reviews, 2026, 31(03), 980–988. Article DOI: https://doi.org/10.30574/wjarr.2026.31.3.2404