A Proactive Framework for Detecting and Preventing Zero-Day Attacks in Modern Network Environments
##plugins.themes.EpsilonTheme.article.main##
Shareefullah Mosazai*
Ikramullah Maroof
Islahuddin Jalal
Zero-day attacks exploit software and network vulnerabilities that are unknown to vendors and defenders, leaving signature-based intrusion detection systems structurally unable to respond before damage occurs. This study proposes a proactive framework that combines unsupervised anomaly detection, ensemble supervised learning, and automated response orchestration to detect and contain previously unseen attacks in modern network environments. The framework integrates a deep autoencoder for reconstruction-based anomaly scoring, an isolation forest for density-based outlier isolation, and a gradient-boosted ensemble for supervised refinement, whose outputs are fused through a weighted threat-scoring module aligned with the MITRE ATT&CK matrix. Detected anomalies trigger an orchestration layer that automatically quarantines affected hosts, updates software-defined network rules, and redirects suspicious traffic to deception environments for analysis. The framework was evaluated on benchmark network-traffic corpora (UNSW-NB15 and CIC-IDS2017) using zero-day scenarios constructed by withholding entire attack categories from training. Results indicate that the hybrid framework achieves higher detection accuracy and a substantially lower false-positive rate than individual base learners and a conventional signature-based baseline, while maintaining detection latency compatible with near-real-time response. These findings suggest that combining complementary unsupervised and supervised models within a proactive orchestration pipeline meaningfully improves resilience against zero-day threats compared with reactive, signature-dependent defenses. The paper further discusses architectural trade-offs, deployment considerations, and directions for future work on adversarial robustness and cross-domain generalization.











