NetFlow Anomaly Detection Dataset Creation for Traffic Analysis
Evita Roponena, Inese Poļaka, Jānis Grabis · 2024
Information and communication technologies (ICT) and their security are essential for large enterprises and higher education institutions to maintain business integrity. These technologies create a large amount of data that should be analysed simultaneously to detect threats in the ICT system to protect the data. NetFlow is a network protocol that can be used to monitor network traffic, collect IP addresses, and detect anomalies in NetFlow. This study provides a method for creating a dataset of real-life NetFlow for anomaly detection using machine learning. The dataset was validated by implementing anomaly detection with the K-means clustering algorithm and time-series forecasting using the long short-term memory method. The study provides a feature dataset for both machine learning methods and an overview of the anomaly detection methods used in this research.