Investigating the performance of Machine Learning algorithms over SMOTE and ADASYN oversampling techniques in Darknet Traffic Classifier System
Anjali Sureshkumar Nair, Prashant Nitnaware · 2024
The clandestine nature of darknet activities has presented an escalating challenge to cybersecurity efforts, necessitating sophisticated methods for identifying patterns in the classification of network traffic associated with these covert operations. One of the most significant challenges in this domain is the inherent class imbalance within Darknet traffic datasets. The malicious traffic, which is often the target of interest, constitutes a minority of the overall data. This imbalance hampers the ability of machine learning algorithms to effectively discriminate between normal and malicious network behavior, leading to a high rate of false negatives and missed threats. Boosting algorithms, such as AdaBoost and Gradient Boosting, coupled with decision trees, offer a formidable combination for effective network traffic classification. The proposed system introduces a novel approach to address this challenge by proposing the development of a multistage machine learning classifier. The classifier, leveraging the synergies between decision trees and boosting algorithms, aims to significantly improve the performance of analysis on the darknet network traffic. To address this issue, this research explores the application of Oversampling techniques namely, Synthetic Minority Oversampling (SMOTE) and Adaptive Synthetic Sampling (ADASYN) for the elimination of the class imbalance issue in the classification of Darknet traffic.