Enhancing Cybersecurity with Machine Learning: Evaluating the Efficacy of Isolation Forests and Autoencoders in Anomaly Detection

Rishabh Sharma, Madhur Grover · 2024

The growing intensity of cyber threats requires security systems with high intellectual capabilities that are dynamically adapting to new challenges. This study explores the utilization of Isolation Forests and Autoencoders in machine learning for anomaly detection. It is for their contribution to cybersecurity to boost it. In this research, an extensive dataset of network traffic that manifests both normal and malicious instances is used to examine the efficacy of these models in detecting anomalous events that may constitute cyber threats. The approach applied involves data collection, preprocessing, the thorough evaluation of the models against metrics such as Anomaly Detection Rate (ADR), Mean Time to Detect (MTTD), False Alarm Rate (FAR), and Detection Consistency (DC) Output shown that applying Isolation Forest has found 85% anomalous record, with a time to detect of 2 seconds and a consistency of 90%, while Autoencoder got slightly lower detecting rate but beats off false alarm by finding only 4%. Unlike traditional methods done by Support Vector Machines and Decision Trees where this model not only was successful but in some cases performed better, it validated their implementation ability and usefulness in the cybersecurity real world. The research presents a major activity of applying Isolation Forests and Autoencoders to cybersecurity systems which elevate their anomaly detection potency. This also explains the importance of combining it with other machine learning models within the existing security systems, for the ability to boost the accuracy in detection and decrease response time to threats. Therefore, this study is one of the crucial pieces in the building of systems that are adaptable and resilient to attacks that continue to be more unpredictable.

Read the paper · More papers on PaperTik