ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Sat 18 Apr 2026 11:15 - 11:30 at Europa II - EnCyCriS Paper Session 2 Chair(s): Eunkyoung Jee

Web servers face escalating security threats, with organizations experiencing a 75% increase in weekly cyberattacks. Traditional rule-based intrusion detection systems struggle to identify novel attack patterns, requiring manual updates for each new threat. We present a real-time anomaly detection system that combines machine learning with stream processing to automatically detect anomalies in Apache web server logs. Through systematic evalua- tion of ten algorithms across classical and deep learning paradigms, we identify optimal configurations through hyperparameter opti- mization. Our optimized Support Vector Data Description model achieves F1-Score of 0.975, demonstrating 41% improvement over the professional Wazuh SIEM system. The system processes pro- duction logs with end-to-end latency under 2 seconds using Apache Kafka. Feature selection reveals five characteristics capture 89% of detection capability while reducing complexity by 88.6%. However, generalization to unseen attack types remains challenging, with 65.8% average performance degradation in Leave-One-Attack-Out evaluation. This work provides practical insights for deploying ML-based intrusion detection in production environments.

Sat 18 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
EnCyCriS Paper Session 2EnCyCriS at Europa II
Chair(s): Eunkyoung Jee KAIST, South Korea
11:00
15m
Full-paper
MCP-Scanner: Detecting Security Risks in Model Context Protocol SystemsVirtual Attendance
EnCyCriS
Parya Abadeh University of Guelph, Martin Lochner (eSentire Inc, Taha Ansari eSentire Inc, Fattane Zarrinkalam University of Guelph
11:15
15m
Full-paper
Real-Time Anomaly Detection in Web Server Logs Using Machine Learning and Apache Kafka
EnCyCriS
Valentina Rojas Osorio University of Chile, Chile, Ángel Jimenez Molina Data and Artificial Initiative - IDIA, Cecilia Bastarrica Universidad de Chile, Chile, Felipe Vildoso Castillo University of Chile, Chile
11:30
10m
Short-paper
A Comprehensive Framework to Secure CBTC Communications
EnCyCriS
Amin Fakhereldine Queen's University, Canada, Mohammad Zulkernine Queen's University, Canada, Jessica Alecci Irdeto, Will Hickie Irdeto
11:40
10m
Short-paper
A Transfer Learning Approach to Unveil the Role of Windows Common Configuration Enumerations in IEC 62443 Compliance
EnCyCriS
Miguel Bicudo UFRJ, Brazil, Estevao Rabello UFRJ, Brazil, Daniel Sadoc Menasche UFRJ, Brazil, Paulo Segal UFF, Claudio Segal UFF, Anton Kocheturov Siemens Technology, Priyanjan Sharma Siemens
Pre-print
11:50
35m
Panel
Main panel discussions
EnCyCriS

12:25
5m
Day closing
Workshop Closure
EnCyCriS
Coralie Esnoul Institute For Energy Technology (IFE)