Enhancing Network Security: Machine Learning Meets Anomaly Detection
Hanen Louati, Yaser Al Mtawa · 2025
Anomaly detection is vital for enhancing network security amidst the growing complexity of cyber threats. This study investigates the effectiveness of machine learning and neural network models in identifying network anomalies using the NFS-2023-TE dataset, an enhanced version of CICIDS-2017, which incorporates realistic TCP flag expiration patterns (e.g., RST and FIN) for improved real-world applicability. Various supervised learning algorithms, including Random Forest(RF), Boosting models, Support Vector Machines (SVM), and Multi-Layer Perceptron (MLP), were evaluated for detecting Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS), and Port Scanning attacks. The analysis revealed that Random Forest and Voting Classifier (VC) achieved superior detection rates, particularly when coupled with advanced feature engineering and oversampling techniques to address imbalanced attack classes. MLP performed effectively in multi-class classification tasks involving TCP flag expirations. These findings underscore the importance of combining realistic datasets, optimized machine learning methodologies, and targeted feature engineering to enhance anomaly detection systems. This research provides valuable insights for cybersecurity professionals to develop more robust strategies for mitigating malicious activities.