Network Anomaly Behavior Detection and Security Protection based on Clustering Algorithm
Tianfu Ma, Jian Bao, Hao Yang, Xuejiao Zhao, Qingwang Zhang, Wanting Lv · 2025
Many existing anomaly detection algorithms are difficult to perform real-time detection in large-scale, high-speed traffic network environments due to their excessive reliance on computationally intensive feature extraction and analysis. Therefore, this article constructs a network anomaly behavior detection model based on clustering algorithm, and uses it to achieve network security protection for enterprises. This article first deeply analyzes the categories and storage forms of network traffic data, then, designs a multi-level and modular network anomaly behavior detection system architecture. Subsequently, this article investigates the implementation of KSAIDS (K-means SMOTE oversampling and Autoencoder Detection System) through the use of k-means SMOTE (Synthetic Minority Over sampling Technique) oversampling method and autoencoder method. At the same time, it is proposed to use decision trees for data mining of network traffic and feature extraction. Finally, through experimental verification in a big data environment, this method has shown excellent performance in identifying and classifying abnormal network behaviors. The specific experimental results show that the detection accuracy of this method reaches 92%, and the false alarm rate is reduced to 5%. Compared with traditional methods, the algorithm explored in this study performs excellently in processing complex network data, significantly improving detection efficiency and system stability.