00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

Development of an Enhanced Ripple Down System for Detecting Cybercrimes in a University Environment

Authors

Adeyemo Rukayat Ayokunmi

Ladoke Akintola University of Technology, Ogbomoso) (Nigeria)

Ismaila Wasiu Oladimeji

Ladoke Akintola University of Technology, Ogbomoso) (Nigeria)

Afolabi Adeolu Olabode

Ladoke Akintola University of Technology, Ogbomoso) (Nigeria)

Adeyemo Isiaka Akinkunmi

Ladoke Akintola University of Technology, Ogbomoso) (Nigeria)

Ismaila Folasade Muibat

Osun State University (Nigeria)

Article Information

DOI: 10.51583/IJLTEMAS.2026.150700170

Subject Category: Education

Volume/Issue: 15/7 | Page No: 2263-2333

Publication Timeline

Submitted: 2026-08-10

Accepted: 2026-08-15

Published: 2026-08-26

Abstract

University environments have become increasingly vulnerable to cybercrimes, including identity theft, hacking, financial fraud, and data breaches. Existing detection systems often exhibit high false positive rates, causing alert fatigue and missed detections, alongside prolonged recognition times that delay response to critical incidents. These limitations undermine the effectiveness of cybersecurity measures in academic institutions. This research aims to develop and evaluate an Enhanced Ripple Down Rule (ERDR) system for detecting cybercrimes in a university environment, addressing the limitations of standard rule-based approaches.
A dataset comprising 3,800 cybercrime records, covering seven crime types (labelled Crime A through G) with four attributes each, was used. The dataset was partitioned into training (2,800 records) and testing (1,000 records) sets. The ERDR system, extending the standard Ripple Down Rule framework, employs a binary tree structure with enhanced rule processing capabilities. The system was implemented using MATLAB (R2023a) on a Windows 10 64-bit platform. Performance was evaluated using Sensitivity, Specificity, False Alarm Rate (FAR), Accuracy, and Computational Time (CT) across multiple threshold values.
At the optimum threshold of 0.80, the ERDR system achieved: Sensitivity of 97.86%, Specificity of 98.92%, FAR of 1.08%, Accuracy of 99.86%, and CT of 140.9 seconds. In comparison, the standard RDR achieved: Sensitivity of 96.24%, Specificity of 95.74%, FAR of 4.26%, Accuracy of 97.85%, and CT of 131.11 seconds.
The ERDR system demonstrated superior performance across all metrics, reducing false alarms by 74.6% while improving accuracy by 2.01%. The system provides a robust, accurate, and practical solution for cybercrime detection in university environments. Its superior performance, particularly in reducing false positives, makes it suitable for deployment across higher education institutions. This research contributes to the field of cybersecurity by extending the Ripple Down Rule methodology with enhancements that significantly improve detection accuracy and operational efficiency.

Keywords

Enhanced Ripple, Nigeria

Downloads

References

1. Alazab, A., Abawajy, J. H., & Hobbs, M. (2013). Web Malware that Targets Web Applications. Social Network Engineering for Secure Web Data and Services, 12, 248-264. doi:10.4018/978-1-4666-3926-3. [Google Scholar] [Crossref]

2. Alex S., David D., Aladdin A. (2018). Intelligent intrusion detection systems using artificial neural networks. The Korean Institute of Communication and Information Science, ICT Express 4, 95–99. [Google Scholar] [Crossref]

3. Ameer A. and Chafika B., (2015). Cybercrime Profiling: Decision-Tree Induction, Examining Perceptions of Internet Risk and Cybercrime Victimization. IEEE Trustcom. [Google Scholar] [Crossref]

4. Amrit, P. S., and Manik, D.S. (2014). Analysis of Host-Based and Network-Based Intrusion Detection System, International Journal of Computer Network and Information Security, 8, PP.41-47. [Google Scholar] [Crossref]

5. Aru, O. E and Chiaghana, C. E. (2018). Malware Analysis and Mitigation in Information Preservation, Computer Engineering (IOSR-JCE), e-ISSN: 2278-0661, 20(4): 53-62. [Google Scholar] [Crossref]

6. Arulogun, O.T., Amusan D. G. (2015). Vehicle license plate recognition using edge detection and neural network. International Journal of Science and Research (IJSR), ISSN (Online): 2319-7064. [Google Scholar] [Crossref]

7. Anderson, R., and Moore, T. (2007). Information security economics and beyond. Advances in Cryptology, 68-91. [Google Scholar] [Crossref]

8. Anderson, B., Storlie, C., and Lane, T. (2012). Improving malware classification: bridging the static/dynamic gap. In Proceedings of the 5th ACM Workshop on Security and Artificial Intelligence, 3–14. [Google Scholar] [Crossref]

9. Asmaa, S. and Sharad, G. (2011). Intrusion detection system and intrusion prevention system. International Journal of Scientific and Engineering Research, 2(7): 64-71. [Google Scholar] [Crossref]

10. Blum, A, Song, D, and Venkataraman, S. (2004). Detection of interactive stepping stones. Algorithms and confidence bounds, in Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID), 27, 1134-1142. [Google Scholar] [Crossref]

11. Burch, H. and Cheswick, B. (2000). Tracing anonymous packets to their approximate source, in Proceedings of USENIX LISA, New Orleans, USA, 319-327. [Google Scholar] [Crossref]

12. Chao, R., Tan, Y. (2009). A Virus Detection System Based on Artificial Immune System, International Conference on Computational Intelligence and Security, 1, 6–10. [Google Scholar] [Crossref]

13. Cker Chiueh, T., and Hsu, F., H. (2001). A Compile-Time Solution to Buffer Overflow Attacks. Proc. 21st Int’l Conf. Distributed Computing Systems (ICDCS). [Google Scholar] [Crossref]

14. Cohen, LE., Felson M. (1979). Social Change and Crime Rate Trends. A Routine Activity Approach. Am. Sociol. 44(2): 588-605. [Google Scholar] [Crossref]

15. Connolly, T. M., Begg, C. E., and Strachan. A. D. (2006). Database systems: Addison-Wesley. Journal of Image and Vision Computing, 19, 142-160. [Google Scholar] [Crossref]

16. Corporation. M., (2012). Common Vulnerabilities and Exposures Available: http://cve.mitre.org/. [Google Scholar] [Crossref]

17. Cova, M., Balzarott D., Felmetsger V., and Vigna, G. (2008). Swaddler: An approach for an anomaly-based detection of state violations in web applications, 63-86. [Google Scholar] [Crossref]

18. Dagorn, N. (2008). A Cooperative Bayesian Anomaly-Based Intrusion Detection System for Web Applications (Extended Abstract), Web IDS: 392-393. [Google Scholar] [Crossref]

19. Danforth, M. (2009). Towards a Classifying Artificial Immune System for Web Server Attacks. International Conference on Machine Learning and Applications, 523–527. [Google Scholar] [Crossref]

20. Dharmapurikar, S., Krishnamurthy. P, Sproull. T, and Lockwood J. W. (2004). Deep Packet inspection using parallel bloom filters. IEEE. 52-61. [Google Scholar] [Crossref]

21. Duman, E. and Ozcelik. H. M. (2011). Detecting credit card fraud by genetic algorithm and scatter search. Science Direct, Expert System with Applications 38, 13057-13063. [Google Scholar] [Crossref]

22. EshghiShargh, A. (2009). Using Artificial Immune System on Implementation of Intrusion Detection Systems. Third UK Sim European Symposium on Computer Modeling and Simulation, 164-168. [Google Scholar] [Crossref]

23. Figueiredo, M. A. (2000). On gaussian radial basis function approximations: interpretation, extensions, and learning strategies. In Proceedings of the IEEE 15th International Conference on Pattern Recognition 2, 618–621. [Google Scholar] [Crossref]

24. Folashade, B. O and Abimbola K.A. (2013). The Nature, Causes and Consequences of Cyber Crime in Tertiary Institutions in Zaria-Kaduna State, Nigeria. American International Journal of Contemporary Research. 3(9): 21-32. [Google Scholar] [Crossref]

25. Garcia K. A. (2012). Analyzing Log Files for Postmortem Intrusion Detection. IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews), 42(6): 1690-704. [Google Scholar] [Crossref]

26. Garcia-Teodoro, P., Diaz-Verdejo, J., Macia-Fernandez. G., and Vazquez. E. (2009). Anomaly-based network intrusion detection. Techniques, systems and challenges, Computers & Security, 28, 18-28. [Google Scholar] [Crossref]

27. Gianini, G., Anisetti, M., Azzini, V., Bellandi, V., Damiani, E., Marrara, S. (2009). An Artificial Immune System approach to Anomaly Detection in Multimedia Ambient Intelligence. 3rd IEEE International Conference on Digital Ecosystems and Technologies. 502–506. [Google Scholar] [Crossref]

28. Hesham, A. and Saeed A. (2011). Bayesian based intrusion detection system. Journal of King Saud University Computer and Information Sciences. 2-7. [Google Scholar] [Crossref]

29. Huang, G., Saratchandran, P., and Sundararajan, N. (2005). A generalized growing and pruning RBF (GGAP-RBF) neural network for function approximation. IEEE Transactions on Neural Networks. 16(1), 57–67. [Google Scholar] [Crossref]

30. Ismaila, W. O, Ismaila, F. M, Falohun, A. S. Oladoye S. F. (2018). Soft Computing Approach to Anomaly Detection in Subscribers Call Profiles. The International Journal of Engineering and Science (IJES). 7(12), 23-30. [Google Scholar] [Crossref]

31. Ismaila, W. O., Falohun, A.S., Ismaila F.M., Ogunjinmi T.O., Babalola O.R. (2019). Soft Computing: Investigation of two-step approach to identify theft detection in electronic payments. The proceedings for Academic Conference of the sub-sahara African Academic Research publications on unleashing sub-sahara African Resources held at Multipurpose Hall, Gonbe State University, Gombe State, Nigeria. 18(2), 13–23. [Google Scholar] [Crossref]

32. Iwarimie, J., D. (2010). Criminology, Crime and Delinquency in Nigeria. Port Harcourt, Pearl Publishers. [Google Scholar] [Crossref]

33. Iwasokun, G. B., Alese, B. K., T A., and Aranuwa, F. O. (2012). Statistical evaluation of the impact of ICT on Nigerian universities. International Journal of Education and Development using Information and Communication Technology (IJEDICT), 8(1), 104-120. [Google Scholar] [Crossref]

34. James l. (2018). Economic Impact of Cybercrime—No Slowing Down. McAfee, one of the world’s leading independent cybersecurity companies. 1-28. [Google Scholar] [Crossref]

35. Jamil F. (2003). Statistical based Intrusion Detection. Symantec. Security Focus. [Google Scholar] [Crossref]

36. Juvonen and Sipola T. (2013). Combining conjunctive rule extraction with diffusion maps for network intrusion detection. 20-13. [Google Scholar] [Crossref]

37. Kim, K, Choi, Y and Park, J. (2013). Pricing fraud detection in online shopping malls using a finite mixture model. Science Direct Electronic Commerce Research and Applications, 195-207. [Google Scholar] [Crossref]

38. Kolbitsch. (2013). Discriminant Malware Distance Learning on Structural Information for Automated Malware Classification. Proceedings of the ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems. 347-348. [Google Scholar] [Crossref]

39. Kruegel, C. Comparetti, P. M., Hlauschek, C. and Bayer, U. (2009). Scalable, Behavior-Based Malware Clustering. IEEE. [Google Scholar] [Crossref]

40. Kruegel, C., Mutz, D., Robertson, W., and Valeur F. (2003). Bayesian event classification for intrusion detection. In Computer Security Applications Conference, 2003. Proceedings. 19th Annual. 14-23. [Google Scholar] [Crossref]

41. Lebbe, M. A., Agbinya, J. I., Chaczko, Z., Chiang F. (2007). Self-Organized Classification of Dangers for Secure Wireless Mesh Networks. Australasian Telecommunication Networks and Applications Conference. 322–327. [Google Scholar] [Crossref]

42. Longe, B., Chiemeke, C. (2008). Cybercrime and criminality in Nigeria. Journal of Social Science. 6(4), 133-139. [Google Scholar] [Crossref]

43. Maher, A., Hossain, M.A., Keshav, D., Fadi, T. (2010). Predicting Phishing Websites using Classification Mining Techniques with Experimental Case Studies. Seventh International Conference on Information Technology. [Google Scholar] [Crossref]

44. Maitanmi, O, Ogunlere S, Ayinde S, Adekunle Y. (2013). Impact of Cyber Crimes on Nigerian Economy. The International Journal Of Engineering And Science (IJES), 2(4), 45-51. [Google Scholar] [Crossref]

45. Manjeri N. K., and Shelke C. J. (2014). Remote Administrative Trojan/Tool (RAT). JCSMC. 3(3), 482–487. [Google Scholar] [Crossref]

46. Moore. T., and Anderson. R. (2007). Information security economics–And beyond. Advances in Cryptology-CRYPTO, 68-91. [Google Scholar] [Crossref]

47. Neelabh (2012). Tracking Digital Footprints of Scareware to Thwart Cyber Hypnotism Through Cyber Vigilantism in Cyberspace. BVICAM’s International Journal of Information Technology (BIJIT). 4(2), 0973–5658. [Google Scholar] [Crossref]

48. Ng, J. D. Joshi, and Banik. S. M. (2015). Applying Data Mining Techniques to Intrusion Detection. Information Technology: New Generations (ITNG) 2015 Proceedings of the 12th International Conference on Information Technology, Las Vegas, NV, USA, 800-810. [Google Scholar] [Crossref]

49. Odumesi, J. O. (2014). A socio-technological analysis of cybercrime and cybersecurity in Nigeria. International Journal of Sociology and Anthropology, 6(3), 116-125. [Google Scholar] [Crossref]

50. Okoye R and Gbegi N. (2013). An evaluation of the effect of fraud and related financial crimes in Nigerian economy. Kuwait chapter of Arabian Journal of Business and Management Review 2(7). [Google Scholar] [Crossref]

51. Open Web Application Security Project. (2010). The Top 10 Most Critical Web Application Security Risks. [Google Scholar] [Crossref]

52. Patcha. A and Park J. M. (2007). An overview of anomaly detection techniques: Existing solutions and latest technological trends. Computer Networks, 51, 3448-3470. [Google Scholar] [Crossref]

53. Parvinder, S., and Mandeep, S. (2015). Fraud Detection by Monitoring Customer Behavior and Activities. International Journal of Computer Applications. 111(11), 0975–8887. [Google Scholar] [Crossref]

54. Powers, S. T., and He, J. (2008). A hybrid artificial immune system and Self Organizing Map for network intrusion detection. Information Sciences, 178, 3024-3042. [Google Scholar] [Crossref]

55. Priyanka, S. (2009). Ripple-Down Rules for Knowledge Acquisition in Intelligent System (JTES) Delving. Journal of Technology and Engineering Sciences. 1(1). [Google Scholar] [Crossref]

56. Quinlan, J. R. (2006). Induction of Decision Trees. Machine Learning, 1, 81-106. [Google Scholar] [Crossref]

57. Razzaq and Abdul. (2014). Semantic Security Against Web Application Attacks: 254 Vol. Elsevier Inc, 2014. [Google Scholar] [Crossref]

58. Reazul K. M., Abdur Rahman O., Tanvir S. (2017). A Network Intrusion Detection Framework based on Bayesian Network using Wrapper Approach. International Journal of Computer Applications. 166(4): 0975–8887. [Google Scholar] [Crossref]

59. Robertson, W. K. (2010). Detecting and preventing attacks against web applications. Information of Technology, University of California, Santa California. [Google Scholar] [Crossref]

60. Roesch, M. (1999). Snort-lightweight intrusion detection for networks. In Proceedings of the 13th USENIX Conference on System Administration. 1.9, 229-238. [Google Scholar] [Crossref]

61. Roger, E.S. (2008). Rogers Communications Inc, 2008 Annual Report. [Google Scholar] [Crossref]

62. Samanvay, G. (2012). Buffer Overflow Attacka. IOSR Journal of Computer Engineering (IOSRJCE), ISSN: 2278-0661, 1(1): 10-23. [Google Scholar] [Crossref]

63. Seong, S.K., and Narasimha R. (2005). A study of analyzing network traffic as images in real-time. In IEEE Infocom. 2056–2067. [Google Scholar] [Crossref]

64. Sesan, G., Soremi, B., and Oluwafemi B. (2013). Economic Cost of Cybercrime in Nigeria. Cyber Steward Network Project of the Citizen Lab. University of Toronto. [Google Scholar] [Crossref]

65. Shafi, K., and Abbass, H. A. (2009). An adaptive genetic-based signature learning system for intrusion detection. Expert Systems with Applications. 36, 12036-12043. [Google Scholar] [Crossref]

66. Sheikhan, M., Jadidi, Z., and Beheshti, M. (2010). Effects of feature reduction on the performance of attack recognition by static and dynamic neural networks. World Applied Sciences Journal, 8, 302-308. [Google Scholar] [Crossref]

67. Shimrit Tzur-David (2011). Network Intrusion Prevention System. Signature-based and Anomaly Detection. Ph.D. Thesis, School Computer Science. The Hebrew University of Jerusalem. [Google Scholar] [Crossref]

68. Simone, A. L. (2019). Applying a Neural Network Ensemble to Intrusion Detection. JAISCR, 9(6). [Google Scholar] [Crossref]

69. Sinclair, C., Pierce, L., and Matzner, S. (2009). An application of machine learning to network intrusion detection. In Computer Security Applications Conference, 1999 (ACSAC'99) Proceedings. 15th Annual. 371-377. [Google Scholar] [Crossref]

70. Singh R., Kumar H., Singla R.K., Ketti, R.R. (2017). Internet attacks and intrusion detection System. A review of the literature, Online Inform. 41(2): 171–184. [Google Scholar] [Crossref]

71. Stakhanova, N., Basu, S., and Wong, J. (2007). A taxonomy of intrusion response systems. International Journal of Information and Computer Security, 1, 169-184. [Google Scholar] [Crossref]

72. Steve U. B, Diepreye O, Uduak D. A. (2009). Information Communication Technologies in the Management of Education for Sustainable Development in Africa. An International Multi-Disciplinary Journal, Ethiopia, 3(3): 414-428. [Google Scholar] [Crossref]

73. Stibor, T., Timmis, J., and Eckert, C. (2005). A comparative study of real-valued negative selection to statistical anomaly detection techniques. In Artificial Immune Systems, Springer, 262-275. [Google Scholar] [Crossref]

74. Sumanjit, D. and Tapaswini N. (2013). Impact of Cyber Crime: Issues and Challenges. International Journal of Engineering Sciences & Emerging Technologies, 6(2): 142-153. [Google Scholar] [Crossref]

75. Tong, X, Wang, Z, and Yu, H. (2009). Hybrid RBF/Elman neural networks for intrusion detection system secure model. Computer Physics Communications, 180, 1795-1801. [Google Scholar] [Crossref]

76. Vigna, G., and Kemmerer, R. A. (2009). A network-based intrusion detection system. Journal of Computer Security. 7, 37-72. [Google Scholar] [Crossref]

77. Vijesh K., Santhadevi P. (2014). Internet spam threats and email exploitation – A scuffle with inbox attack. Int. Journal of Applied Sciences and Engineering Research, 3(4): 46-55. [Google Scholar] [Crossref]

78. Wang, G, Hao, J, Ma, J, and Huang, L. (2010). A new approach to intrusion detection using Artificial Neural Networks and fuzzy clustering. Expert Systems with Applications, 37, 6225-6232. [Google Scholar] [Crossref]

79. William R. Cheswick., Steven M. Bellovin., Aviel D. R. (2003). Firewalls and Internet Security. Repelling the Wily Hacker, 2nd Edition, Addison Wesley Publication. [Google Scholar] [Crossref]

80. Wu J., Peng D., Li Z., Zhao L., Ling H. (2015). Network intrusion detection based on a general regression neural network optimized by an improved artificial immune algorithm. PLOS ONE, 10(3): 1–13. [Google Scholar] [Crossref]

81. Yeh, Y.R., Lee, Y.J., and Wang, Y.C.F. (2013). Anomaly Detection via Online Oversampling Principal Component Analysis. IEEE Transactions on Knowledge and Data Engineering, 25(7): 1460-1470. [Google Scholar] [Crossref]

82. Yoohwan, K., Wing, C., Lau, M., Choo, C., and Jonathan, C. (2004). Statistics-based overload control against distributed denial-of-service attacks. In IEEE Infocom, 2594–2604. [Google Scholar] [Crossref]

83. Zhang, A., Chen, C., and Karimi, H. (2013). A new adaptive LSSVR with on-line multikernel RBF tuning to evaluate analog circuit performance. Abstract and Applied Analysis. 20, 1-7. Article ID 231735. [Google Scholar] [Crossref]

84. Zou, C. Towsley, Gong, W. & Cai. Routing S. (2015). Worm: A fast, selective attack worm based on IP address information. In Proc. IEEE Work. Princ. Adv. and Dist. Simul. (PADS), 199–206. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.