The ADS System for Real-Time Anomaly Detection with Scalable and SMART Monitoring in a Data Network

Basel A. Dabwan, Amodi Abdullah, Zakhriya Alhassan, Somia Badawi, Nabila Saeed, Yahya A. Ali · 2025

The This study presents an automated anomaly detection framework for analyzing cybersecurity datasets, focusing on network traffic and server performance logs. Using the Isolation Forest algorithm, we examined four datasets: a large-scale network traffic file (a01.dat with ~2.9M samples) and three server logs (cv_server_data.csv, gt_server_data.csv, and tr_server_data.csv). The goal was to identify irregular patterns indicative of cyber threats or system failures. Data preprocessing included normalization and missing-value imputation. The Isolation Forest model, configured with 200 estimators and 5% contamination, detected anomalies across all datasets. Results revealed 147,155 anomalies (4.98%) in a01.dat, while server logs showed 2.94–5.23% anomaly rates, with cv and tr datasets exhibiting higher outliers (5.23%) compared to gt (2.94%). Feature importance analysis highlighted key metrics (e.g., packet frequency, response times) correlated with anomalies. The framework achieved efficient processing, even for large datasets, with parallel task completion in <15 seconds for 200-tree ensembles. Visualizations (time-series and 2D scatter plots) demonstrated clear separation of anomalies. These findings suggest that lightweight unsupervised methods can effectively flag suspicious activity in heterogeneous IT infrastructure.

Read the paper · More papers on PaperTik