Detectify: Leveraging Isolation Forest and K-Means for Optimized Network Traffic Anomaly Detection
Raju Gudla, Satyanarayana Vollala, Anushka Ekka, Shristi Ray, Ruhul Amin · 2025
Network security is the most essential aspect in today's world, that is, always being digitally connected, and being able to recognize abnormalities is important for defending against cyber attacks. Because regular security systems are not adequate for selective complex infiltrations, this often leads to the development of advanced machine learning models that will supplement the usual anomaly detection capabilities. Network intrusion has been evaluated using algorithms based on NSLKDD dataset that is commonly utilized as a yardstick. However, this study fills this gap, producing effective as well as reliable anomaly detection systems. We preprocessed the data in a comprehensive manner, chose features and used advanced methods like Isolation Forest, K-Means clustering, and Synthetic Minority Over-sampling Technique (SMOTE) in order to improve the quality of logistic regression,$k$-nearest neighbors and random forest performance through traditional models. Our findings prove much better in detection giving 99.33% accuracy. This means our proposed methodology is good at spotting threats and doing something about them. Application of Isolation Forest technique in anomalous traffic detection has brought unimaginable improvements in separating the two types of networks: legitimate one and malicious ones. The aforementioned is evidenced by our advanced models consistently outshining traditional methods, indicating that these techniques have the potential to strengthen network security against the growing threats of cybercrime through the amalgamation of K-Means clustering and SMOTE algorithms. Our sophisticated models have continued to surpass conventional methods, showcasing the versatility of these techniques in enhancing network security against emerging cyber threats.