<p>Network Anomaly Detection (NAD) plays a critical role in securing digital infrastructures by identifying deviations from normal network behavior that may indicate malicious activity. As cyber threats become increasingly sophisticated, the focus has shifted from traditional statistical methods to more adaptive approaches based on Machine Learning (ML) and Deep Learning (DL). ML algorithms have demonstrated significant success in classifying network traffic, while DL techniques have gained traction for their scalability and effectiveness in processing large, high-dimensional datasets in real-time environments. This paper presents a comprehensive review and critical analysis of 165 peer-reviewed research articles, comprising 92 studies focused on ML-based NAD techniques and 73 on DL-based approaches. The review categorizes and evaluates various approaches, highlighting their detection capabilities, computational complexities, strengths, and limitations. To evaluate the practical performance of these approaches, the paper conducts experimental analyses using five widely adopted benchmark datasets: NSL-KDD, UNSW-NB15, CICIDS2017, CSE-CICIDS2018, and ToN_IoT. Performance is assessed using standard metrics such as Accuracy, Precision, Recall, and F1-score, alongside the Matthews Correlation Coefficient (MCC). MCC is especially valuable for its ability to deliver balanced evaluation on imbalanced datasets, offering deeper insight into the detection of minority attack classes. Furthermore, the experimental comparison serves as a practical guideline for selecting appropriate ML or DL techniques based on dataset characteristics and network deployment scenarios. The study further proposes seven research questions (RQs) that capture key challenges and insights derived from both the literature and empirical findings. These RQs reflect the critical issues and decision points encountered by network security researchers and practitioners in the development of NAD systems. The paper also concludes with the need and importance of DL techniques, focusing on open issues and potential future directions of DL techniques in the context of NAD.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Machine Learning and Deep Learning Models for Anomaly Intrusion Detection in Networks: A Systematic Review

  • Niharika Sharma,
  • Bhavna Arora

摘要

Network Anomaly Detection (NAD) plays a critical role in securing digital infrastructures by identifying deviations from normal network behavior that may indicate malicious activity. As cyber threats become increasingly sophisticated, the focus has shifted from traditional statistical methods to more adaptive approaches based on Machine Learning (ML) and Deep Learning (DL). ML algorithms have demonstrated significant success in classifying network traffic, while DL techniques have gained traction for their scalability and effectiveness in processing large, high-dimensional datasets in real-time environments. This paper presents a comprehensive review and critical analysis of 165 peer-reviewed research articles, comprising 92 studies focused on ML-based NAD techniques and 73 on DL-based approaches. The review categorizes and evaluates various approaches, highlighting their detection capabilities, computational complexities, strengths, and limitations. To evaluate the practical performance of these approaches, the paper conducts experimental analyses using five widely adopted benchmark datasets: NSL-KDD, UNSW-NB15, CICIDS2017, CSE-CICIDS2018, and ToN_IoT. Performance is assessed using standard metrics such as Accuracy, Precision, Recall, and F1-score, alongside the Matthews Correlation Coefficient (MCC). MCC is especially valuable for its ability to deliver balanced evaluation on imbalanced datasets, offering deeper insight into the detection of minority attack classes. Furthermore, the experimental comparison serves as a practical guideline for selecting appropriate ML or DL techniques based on dataset characteristics and network deployment scenarios. The study further proposes seven research questions (RQs) that capture key challenges and insights derived from both the literature and empirical findings. These RQs reflect the critical issues and decision points encountered by network security researchers and practitioners in the development of NAD systems. The paper also concludes with the need and importance of DL techniques, focusing on open issues and potential future directions of DL techniques in the context of NAD.