With cybersecurity threats constantly evolving, legacy signature-based network defense systems are inadequate to detect newly emerging attacks in real time. This paper proposes an unsupervised machine learning approach for real-time detection of anomalies in network traffic. We develop a system architecture and methodology leveraging isolation forest, autoencoder, and one-class SVM models for identifying anomalies. The models are continually retrained on streaming data using efficient incremental learning procedures for adaptability. We evaluate the detection performance on the NSL-KDD and UNSW-NB15 datasets, analyzing accuracy, overhead, and latency trade-offs. Our experiments demonstrate up to 12% improvement in threat detection over conventional neural network models. The proposed system provides an automated, rapidly adaptable anomaly detection framework to strengthen cyber-defense in real time.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Real-Time Network Traffic Anomaly Detection Using Unsupervised Machine Learning

  • Prince Kumar Singh,
  • Jyoti,
  • Jyotirnob Sharma,
  • Manas Singh

摘要

With cybersecurity threats constantly evolving, legacy signature-based network defense systems are inadequate to detect newly emerging attacks in real time. This paper proposes an unsupervised machine learning approach for real-time detection of anomalies in network traffic. We develop a system architecture and methodology leveraging isolation forest, autoencoder, and one-class SVM models for identifying anomalies. The models are continually retrained on streaming data using efficient incremental learning procedures for adaptability. We evaluate the detection performance on the NSL-KDD and UNSW-NB15 datasets, analyzing accuracy, overhead, and latency trade-offs. Our experiments demonstrate up to 12% improvement in threat detection over conventional neural network models. The proposed system provides an automated, rapidly adaptable anomaly detection framework to strengthen cyber-defense in real time.