Threatlocke: An Anomaly Based Detection Model
James Aaron Heramil, Kyle Dumbrique, Mariah Rocita Mirarza, Lionel Kerwin Ejorango, Roselle Wednesday Gardon, Lorena W. Rabago · 2023
This research paper tests and evaluates the detection rate and efficiency score of the K-Nearest Neighbors(KNN) algorithm as used in an anomaly-based network attack detection model. The model developed will be evaluated on its accuracy, precision, recall, and F1 Score. In order to achieve this, simulated tests were conducted within East-West traffic. In these tests, the model is to detect Denial-of-Service (DoS) attacks based on the following: average packet length, payload average length, and packet time interval. Results of these tests show that integrating the KNN algorithm in an anomaly detection model was able to obtain 92 percent accuracy, 92 percent recall, 100 percent in precision, and a 95.8 percent F1 Score. Using KNN in an anomaly-based detection model was also able to reach a running time of O(n) time complexity compared to other algorithms. This strengthens the conclusion that using the KNN algorithm is viable in detecting anomalous network behavior but has proven to be inefficient during testing based on bits time complexity.