Machine Learning for Network Intrusion Detection

Martina Troesch, Ian Walsh · 2014

Cyber security is an important and growing area of data mining and machine learning applications. We address the problem of distinguishing benign network trac from malicious network-based attacks. Given a labeled dataset of some 5M network connection traces, we have implemented both supervised (Decision Trees, Random Forests) and unsupervised (Local Outlier Factor) learning algorithms to solve the binary classication problem of whether a given connection is normal or abnormal (malicious). Our results for LOF are mixed and hard to interpret, but with Decision Trees we are able to achieve prediction accuracies of over 90% for both normal and abnormal connections. Posterior analysis of the best-performing trees gives us new insight into the relative importance of dierent features for attack classication and suggests future avenues to explore. 1 Background

Read the paper · More papers on PaperTik