Automated Anomaly Detection and Threat Classification in Network Traffic
Krishnaja Venkata Naga Sri Lasya P, Munisaiteja Sharan Tupakula, Naresh Sammeta · 2025
Organizations need automated detection technology since security threats become increasingly complicated. The automatic anomaly detection framework established by research work provides organizations with real-time anomaly detection capabilities for their network traffic records analysis. The study performs performance testing for evaluating four machine learning systems. The research determined Random Forest(RF) Classifier and Logistic Regression as well as Decision Tree(DT) Classifier and K-Nearest Neighbors(KNN) Classifier as suitable options for threat classification frameworks. F1-score joins with accuracy, recall and precision to serve as the main evaluation metrics throughout the testing phase. The system employs a log reader automation that automatically handles unmarked test data for threat identification requirements with integrated security threat detection capabilities. Model choice requirements for security needs differ according to practical situations which leads to significant variations in performance based on strengths and weaknesses. Real-time corporate implementation becomes feasible through this top-performing model since it shows exceptional detection ability together with reliable operational behavior. Businesses need to select specific security models based on their personal security requirements according to the research findings. The research findings enable practitioners to select appropriate machine learning platforms which strengthen corporate cybersecurity infrastructure by running them on intrusion detection systems and malware recognition and network security operations.