Detection of network anomalies in log files using machine learning methods

V. A. Skazin, Aleksey Pavlychev, Sergey Sergeevich Zotov · IOP Conference Series Materials Science and Engineering · 2021

Abstract Detection of network anomalies plays an important role in ensuring information security and countering unauthorized access to information infrastructure, including critical facilities. Detecting of abnormal events in log files is complicated by the fact that individual events without any context may be uninformative. The growing importance of log file analysis in large computer systems requires the development of automated methods for processing unstructured data that retrieves information from large log files without human intervention. This article discusses K-means data clustering method and Isolation forest and OSVM machine learning algorithms in terms of searching network anomalies in network log files in order to detect malicious domains.

Read the paper · More papers on PaperTik