Return to International Journal of Science Transformation and Engineering Innovations
Research Article International Journal of Science Transformation and Engineering Innovations

ENSEMBLE MACHINE LEARNING MODELS FOR REAL-TIME NETWORK INTRUSION DETECTION USING SNMP DATA: A SYSTEMATIC REVIEW

Bukola A. Ifedayo-Ojo*,Boniface K. Alese,Akintoba E. Akinwonmi

Federal University of Technology, Akure, Nigeria.

Department of Cyber Security, Federal University of Technology, Akure, Niger

Department of Computer Science, Federal University of Technology, Akure, Nigeria

* Correspondence: baifedayo-ojo@futa.edu.ng

Abstract

Due to the rising sophistication and frequency of cyberattacks targeting business, cloud, Internet of Things (IoT), and software-defined network settings, Network Intrusion Detection Systems (NIDS) remain critical components of current cybersecurity architecture. Traditional intrusion detection systems (IDSs), which rely primarily on single machine learning algorithms or signatures, have limitations in identifying zero-day attacks, reducing false alarms, and adapting to changing network conditions. As a result, ensemble machine learning techniques have attracted significant interest due to their ability to improve detection accuracy and reduce falsepositive rates. However, their effectiveness is strongly dependent on the quality of the input data. Simple Network Management Protocol (SNMP) data offers a lightweight, scalable, and standardised alternative to packet-level traffic analysis in intrusion detection systems. This review employs the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines to identify, evaluate, and synthesise relevant articles published between 2015 and 2025 on the use of ensemble machine learning models for real-time network intrusion detection using SNMP data. This study analyses commonly used ensemble approaches, SNMP Management Information Base (MIB) features, datasets, evaluation metrics and computational efficiency issues. Electronic databases were searched with predefined Boolean searches. Results show that the most widely used methods for SNMP-based intrusion detection include Random Forest, AdaBoost, Gradient Boosting, XGBoost, and stacking ensembles. It also highlights issues such as dataset imbalance, computational overhead, lack of standardised SNMP datasets and real-time deployment limits. The study concludes that combining ensemble learning with SNMP-MIB data is a good approach to developing flexible and scalable intrusion detection systems for modern cybersecurity environments.

Keywords

Network Intrusion Detection SystemEnsemble LearningMachine LearningReal-time Intrusion DetectionSNMP Data

Full Text Available in PDF

This article is subscription based. Article details are public, while the full PDF is available after access approval.