Enhancing Endpoint Security Through AI Powered Anomaly Detection in Endpoint Logs using Local Outlier Factor (LOF)
Akbar Badhusha Mohideen, P Tharun Sai, Y. Subhan Basha, Shaik Sohel, Y. Venkateswara Reddy · 2025
In today's digital era cybersecurity landscape, endpoint security remains a critical concern due to the increasing sophistication of cyber threats. This study explores anomaly detection using AI-powered techniques to enhance endpoint security by identifying malicious login attempts. The publicly available BETH dataset, which includes authentication logs and security event data, was utilized to conduct a comprehensive analysis of user behavior and potential threats. Three machine learning classifiers namely One-Class SVM, Isolation Forest, and Local Outlier Factor (LOF) were employed for anomaly detection. Among these, LOF, a density-based algorithm, demonstrated the highest accuracy (95%), outperforming Isolation Forest (90%) and One-Class SVM (68.84%). In addition to this, outlier detection techniques, such as box plots, were applied to visualize and analyze data anomalies. The results indicate that density-based anomaly detection methods outperform traditional approaches in identifying security threats. This research proposes the efficiency of AI-based anomaly detection in cybersecurity and underscores the potential of machine learning for real-time Anomaly detection.