Network Traffic Classification using Machine Learning: A Review of Decision Tree, Random Forest, and SVM Approaches on CIC-IDS2017

Authors

  • Gohar Rahman University Malaysia Sabah
  • Ahmad Razin Bin Mohd Zaidi Cybersecurity Research Lab, Faculty of Computing and Informatics, Universiti Malaysia Sabah, Kota Kinabalu, Malaysia

DOI:

https://doi.org/10.51200/ijmic.v3i1.7239

Keywords:

Network Traffic Classification, Machine Learning, CIC-IDS 2017, Intrusion Detection

Abstract

Cyber-attacks are proliferating rapidly, and networks today are increasingly complex. For this reason, the ability to sort and locate intrusions in network traffic is critical. Researchers have employed methods based on machine learning (ML) as the conventional automated and signature focused detection methods often fail to catch newly emerged attack patterns. The purpose of this work is categorized as the survey is to review state-of-the-art machine learning (ML) network traffic classification techniques, focusing on one specific dataset, i.e., the CIC-IDS 2017 dataset and provides an analysis of today’s research. The study drew on the IEEE Xplore, Springer and Elsevier databases for conducting an extensive review of literature published between 2020 and 2024 having identified studies involving supervised machine learning methods like Decision Trees, Random Forest, Support Vector Machine (SVM) that detected desirable and undesirable traffic. Researchers have also reviewed examples of performance measures such is accuracy, precision, recall and F1-score in different studies to determine areas of strength/weakness or patterns. Studies show that Decision Trees are interpretable, Random Forest has good memory and generalization abilities and SVM is accurate but it requires computational optimization in large datasets. Despite these benefits, challenges such as dataset imbalance, feature redundancy, and real-time implementation continue to remain unsolved. This paper has shown how machine learning can improve the network intrusion detection and challenging issues that need to be addressed in further. The obtained insights lead to a basis for an enhanced scalable and robust traffic classification model, contributing to the goals of current research in this domain.

Author Biography

Ahmad Razin Bin Mohd Zaidi, Cybersecurity Research Lab, Faculty of Computing and Informatics, Universiti Malaysia Sabah, Kota Kinabalu, Malaysia

Cybersecurity Research Lab, Faculty of Computing and Informatics, Universiti Malaysia Sabah,
Kota Kinabalu, Malaysia

Published

2026-07-31

How to Cite

Rahman, G., & Ahmad Razin Bin Mohd Zaidi. (2026). Network Traffic Classification using Machine Learning: A Review of Decision Tree, Random Forest, and SVM Approaches on CIC-IDS2017. International Journal of Machine Intelligence and Computing, 3(1), 1–27. https://doi.org/10.51200/ijmic.v3i1.7239
Total Views: 2 | Total Downloads: 0