Investigation the Impact of Features on Malicious Traffic Identification Based on Different Machine Learning Algorithms Combined with Dimensionality Reduction
Runze Wang · 2023
With the Internet's rapid evolution, the incidence of cyberattacks has surged significantly. Employing machine learning to precisely detect and thwart malicious network traffic has emerged as a novel and effective solution for safeguarding computer networks. This research program centers on the identification of suitable machine learning models and the meticulous curation of data features. Within this study, a total of 13 features, encompassing conventional timestamps, the volume of traffic packets in data streams, and their associated sizes, are extracted as key features following the dataset's traffic packet consolidation process. Three algorithms such as Random Forest, Decision Tree and Support Vector Machine were chosen for training and testing the dataset. In addition, Principle Component Analysis dimensionality reduction is performed for these 13 features to determine the effect on the accuracy of the results before and after the dimensionality reduction process. The final result is that the Random Forest algorithm achieves best processing power, but produces large fluctuations in the accuracy in one dimension. In the face of large-scale network traffic analysis, the random forest model should be preferred as the machine learning model, while ensuring that the dimension is greater than one dimension after dimensionality reduction.