Abstract
Network intrusion detection systems must identify known attacks while remaining sensitive to previously unseen or behaviorally unusual traffic. Single detection paradigms are limited because signature-based methods depend on known attack patterns, supervised classifiers may miss behavior outside their training distribution, and anomaly detectors may generate false alarms when legitimate traffic changes. This study presents an intelligent hybrid network intrusion detection system that combines signature-based detection, LightGBM supervised classification, and Isolation Forest anomaly detection in a sequential pipeline. The system was implemented as a Python/Flask application with passive packet monitoring and manual analysis of JSON/CSV traffic records. HIKARI-2021 was used for supervised training. The dataset contained 555,278 records; after preprocessing, 81 features were retained. A stratified 80:20 train-test split was used for LightGBM, while Isolation Forest was trained on 414,065 benign training records. LightGBM was configured with 250 estimators, a learning rate of 0.05, 48 leaves, class weighting, and a tuned decision threshold of 0.7987. On the test set, the classifier achieved 90.60% accuracy, 94.63% weighted precision, 90.60% weighted recall, and 92.01% weighted F1-score. The suspicious-class recall was 81.89%, while suspicious-class precision was 40.50%. The ROC curve produced an AUC of 0.9522. The results demonstrate that the supervised component provides useful discrimination, while the hybrid architecture supplies complementary signature and anomaly-detection mechanisms. Because the available experiment did not produce a separate end-to-end quantitative evaluation of the complete hybrid pipeline, the reported numerical metrics are explicitly attributed to the LightGBM component.