A Hybrid Model for Network Anomalies Classification Based on Improved Random Forest and Frequent Itemset Matching
Ruiyang Zeng, Bing Jiang · 2024
With the advancement of network technology, the methods of network attacks have become increasingly diverse. To counter these threats, traditional machine learning and deep learning techniques have been employed to detect and classify network traffic, leading to significant progress in the field. However, single classification methods often struggle with distinguishing between data categories that share similar characteristics, and there has been limited exploration of hybrid models for classifying anomalous network traffic. In this paper, we develop a hybrid model composed of a improved Random Forest classifier and frequent itemset mining to address these challenges by studying anomalous network traffic data. Through various evaluation metrics and experiments, we demonstrate that this hybrid model effectively leverages the advantages of different classification methods while mitigating the confusion inherent in single-model classifications. The final classification results outperform those achieved by single classifiers without hybridization.