Enhancing Network Security: ML-Based Anomaly Detection

D.S B N S Rekha, V. S. S. P. Raju Gottumukkala, Gudapati Diana Kamal, Shalini Eda · 2024

In network security, theory data is the guiding ideas and principles for anomaly detection algorithms. Theory behind machine learning, statistical analysis, and network protocols is covered in the material. Normal behavior is usually represented by statistical models such as Gaussian distributions. Anomaly detection is made possible by these models, which can spot outliers. Algorithms of Machine Learning(MLA) including Naive Bayes(NB), Logistic Regression (LR), Decision trees(Dt), and Random forests (RF) are used to categorize network traffic. Ports, protocols, packet sizes, timestamps, and IP addresses of both source and destination are some of the criteria that determine this categorization. A thorough understanding of protocols like TCP, UDP, and ICMP is necessary for accurate analysis of network traffic patterns. Anomaly detection programs may be better built with the use of theoretical data, which includes details on typical attack vectors and penetration techniques. Merging theoretical knowledge with actual applications is an excellent strategy for developing robust anomaly detection systems to protect network infrastructures from security risks.

Read the paper · More papers on PaperTik