Application of Machine Learning Models for Device Identification in Wireless Network Traffic
Roger Nick Anaedevha · 2024
T Variants of vulnerabilities in wireless network are rapidly increasing as a result of emerging network traffic complexities. The addition of network communication protocols, weak credentials, privacy requirements, insecure packets encryption, and so forth, amount to demands for more efficient intrusion detection techniques and higher identification accuracy of devices that are within and outside the networks traffic. Consequentially, machine learning and deep learning algorithms such as K – Nearest Neighbor (KNN), Random Forest (RF), Support Vector Machine (SVM), Gaussian Naive Baye (NB), Convolutional Neural Network (CNN), and Deep Belief Networks (DBN), have been helpful as individual model and as a combination in providing solutions to this security and privacy of traffic data over recent time. However, none of these used algorithms or a couple of them may have been able to incorporate the three categories of modeling traffic datasets to identify devices within a network, which includes using the components of the TCP/IP features, the MAC address features, and a combination of both for wholesome trace, prediction, and identification valid for real – time traffic management. This may have been due to individual limitations of the algorithms to different datasets and performance levels. Therefore, this research experiment with Grid Search algorithms coupling KNN, DT, RF, SVM, NB, Isolation Forest algorithm (IFA), Local Outliers Factor (LOF), and Self Organizing Map (SOM), to develop encompassing device identification models. As a result, RF performs best at predicting network devices by 99% in accuracy, precision, recall, specificity, and F1 score in the TCP/IP dataset. SVM performs best with 99% accuracy on the K – means clustering of classes corresponding to each cluster of features in identifying network devices when using the MAC address datasets. And using the Mahalanobis distance with IFA, LOF and SOM, the LOF performs 99% more accurate than others in modeling the combined TCP/IP and MAC address dataset to identify new and anomaly devices within the network traffic. It is therefore recommended that depending on the available dataset that a network administrator and security analyst could obtained from the network traffic will determine the best machine level model, and best tunning of the models’ hyperparameters to identify devices within the network traffic and be able to manage such devices.