Unveiling Network Anomalies: A Comparative Study of Real-time Log-Based Detection Approach
Deepika Marella, Roopa Navya Muthi, Buchammagari Avinash Reddy, Kaniganti Priyanka Saraswathi, Vijender Busi Reddy, Nenavath Srinivas Naik · 2023
In this paper, we address the issue of detecting anomalies in network log files. In laboratory setup, log files are generated by network devices such as routers, switches, firewalls, and servers. These log files contain information about network activities, such as network traffic, device configurations, user activity, and security events. Analyzing log files on computer networks is essential for identifying potential security threats and network issues. Researchers have sought to develop quick and effective methods to identify anomalies in a computer system by examining its log data as a result of this significant utility. In our work, we have used a machine-learning approach called Isolation Forest (iForest) and also examined clustering algorithms, Ordering Points To Identify Cluster Structure, referred to as OPTICS Clustering, and the Density-Based Spatial Clustering of Applications with Noise (DBSCAN) algorithm, for detecting anomalies in real-time log datasets. The performance of each model is evaluated and compared. Finally, we conclude by presenting the experimental results that demonstrate the effectiveness of the suggested method and future directions in real-time log-based anomaly detection, highlighting the need for more advanced and efficient methods to deal with the increasing complexity and scale of modern networks.