Optimizing Network Traffic Anomaly Detection with Normalized Features

Sami Jamil Aljarrah, Sarra Cherbal, Ashraf S. Mashaleh, Mohammad Alauthman, Amjad Gawanmeh · 2024

This paper presents a threshold-based anomaly detection method that combines exponentially weighted normalized features. The method utilizes on two critical metrics: Flow Bytes per Second and Maximum Packet Length, which have shown strong correlations with various types of anomalies in network attacks. The paper presents a method for selecting optimal threshold values that maximize detection accuracy while minimizing false positives. The proposed approach normalizes these features and defines a combined threshold function that integrates the information from both metrics, this is necessary to overcome the sensitivity of each metric when considered alone for anomaly detection. By applying threshold-based anomaly detection on the used dataset, the method identifies an optimal threshold of 6.81 that effectively distinguishes normal from anomalous network behavior. The results demonstrate the effectiveness of the exponential weighting method in identifying anomalies while maintaining sensitivity to ranges of various parameters in network traffic.

Read the paper · More papers on PaperTik