Network Anomaly Detection Using Advanced Machine Learning
Ahmed, Intisam (2025)
Ahmed, Intisam
2025
Tietotekniikan DI-ohjelma - Master's Programme in Information Technology
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2025-06-10
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202506096964
https://urn.fi/URN:NBN:fi:tuni-202506096964
Tiivistelmä
A distributed denial of service (DDoS) attack is one of the biggest challenges in network security today, as it has a large spread of attackers, a complicated attack structure and is always changing over time, so standard detection methods don’t work anymore. Nowadays, using techniques such as RNNs and LSTM networks with machine learning helps have good results against such threats. They perform superbly in finding timing patterns in the network traffic which is vital for finding both typical and unusual kinds of traffic. The authors combine PCA and SMOTE with RNN and LSTM to create an early-detection financial fraud system through this research. PCA allows you to narrow down the number of features to process without losing key information which is beneficial for your system. The common issue of imbalanced data in anomaly detection is solved by SMOTE which creates new samples of rare threats.
After proposing the method, it is tested on a benchmark dataset that anyone can use, showing top detection success, low false positives and better results than standard machine learning approaches. They reveal that box structures supported by better preprocessing may make the network more efficient at defending against complex DDoS attacks.
After proposing the method, it is tested on a benchmark dataset that anyone can use, showing top detection success, low false positives and better results than standard machine learning approaches. They reveal that box structures supported by better preprocessing may make the network more efficient at defending against complex DDoS attacks.
