Leveraging Big Datasets for Machine Learning-Based Anomaly Detection in Cybersecurity Network Traffic
2025
In order to improve cybersecurity and stop criminal activity, network traffic anomaly detection is essential.Anomaly detection is an essential part of cybersecurity, which is necessary to find complex and until undiscovered network threats that frequently evade detection techniques based on signatures and heuristics.This study proposes a comprehensive machine learning framework employing the Random Forest (RF) algorithm, combined with an advanced data preprocessing pipeline encompassing data cleaning, encoding of categorical features, class balancing using SMOTE, feature selection, and normalization to enhance model input quality.The method is tested on the well-known CICIDS2017 dataset, which records a wide variety of current cyberattacks and safe network activity.The suggested RF model performs exceptionally well, attaining 99.88% accuracy, precision, recall, and F1-score.According to comparative findings, the RF model performs much better than baseline methods like K-Nearest Neighbors and Linear Regression, which obtained far lower evaluation metrics.In increasingly complex digital settings, these findings highlight the model's scalability, durability, and applicability for real-time intrusion detection, which helps to create cybersecurity defenses that are more resilient and adaptable.