Log-Based Event Analysis for Network Forensics: An Ensemble Approach with Heterogeneous Logs

Asif Iqbal Hajamydeen, Shahswiene Suthas, Muhammad Irsyad Abdullah · 2025

Since cyber threats are increasing rapidly, keeping digital infrastructures safe now depends on network logs. However, managing a huge number of complicated log data from numerous sources is very difficult with standard singlemodel approaches. An ensemble framework is presented in this research to analyze events from logs with Random Forest, Isolation Forest and Multi-Layer Perceptron classifiers for better anomaly detection. We use preprocessing, PCA for reducing how much data we need and a voting strategy to manage log data from different firewalls, intrusion detection systems, servers and applications. On the KDD Cup 99 dataset, using synthetic noise injection, experiments resulted in an accuracy of 99.96%. Plus, 100% of normal events were discovered and 99% of the abnormal events were detected. The combined approach showed a better performance of up to 20%, when measured against all the individual classifiers. Because it has adaptive threshold control and can handle problems quickly, it fits for network settings that are always changing. Findings reveal that putting together different log data and using ensemble learning helps in building strong forensics tools.

Read the paper · More papers on PaperTik