[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118852-en":3,"doc-seo-118852-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118852,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Applying machine learning to categorize distinct categories of network traffic","The rapid growth of data science enables machine learning across domains where computer network traffic classification has traditionally relied on static, hand-crafted rules that degrade when application behavior or protocols change. The study evaluates multiple classical machine learning approaches for classifying network traffic by exploiting statistical similarities between traffic classes instead of fixed traffic identifiers. Captured network data are processed into flow-based statistical features for 10 application labels across video conferencing, streaming, gaming, and web browsing, then tested using several classifiers. Results show that widely available simple models achieve high accuracy, with the best random forest model reaching 89% accuracy and strong macro-averaged F1 and recall, highlighting maximum packet size–related features as key indicators.","Eastern Michigan University  \nDigitalCommons@EMU  \n\n| Senior Honors Theses and Projects | Honors College |\n| --- | --- |\n| 2023\u003Cbr>Applying machine learning to categorize distinct categories of network traffic\u003Cbr>Isaac M. Dunham\u003Cbr>Follow this and additional works at: [https://commons.emich.edu/honors](https://commons.emich.edu/honors)\u003Cbr> Part of the Information Security Commons |  |\n\nRecommended Citation  \nDunham, Isaac M., \"Applying machine learning to categorize distinct categories of network traffic\" (2023) . Senior Honors Theses and Projects. 785.  \n[https://commons.emich.edu/honors/785](https://commons.emich.edu/honors/785)  \nThis Open Access Senior Honors Thesis is brought to you for free and open access by the Honors College at DigitalCommons@EMU. It has been accepted for inclusion in Senior Honors Theses and Projects by an authorized administrator of DigitalCommons@EMU. For more information, please contact [lib-ir@emich.edu](lib-ir@emich.edu).  \nApplying machine learning to categorize distinct categories of network traffic  \nAbstract  \nThe recent rapid growth of the field of data science has made available to all fields opportunities to leverage machine learning. Computer network traffic classification has traditionally been performed using static, pre-written rules that are easily made ineffective if changes, legitimate or not, are made to the applications or protocols underlying a particular category of network traffic. This paper explores the problem of network traffic classification and analyzes the viability of having the process performed using a multitude of classical machine learning techniques against significant statistical similarities between classes of network traffic as opposed to traditional static traffic identifiers.  \nTo accomplish this, network data was captured, processed, and evaluated for 10 application labels under the categories of video conferencing, video streaming, video gaming, and web browsing as described later in Table 1. Flow-based statistical features for the dataset were derived from the network captures in accordance with the “Flow Data Feature Creation” section and were analyzed against a nearest centroid, k-nearest neighbors, Gaussian naïve Bayes, support vector machine, decision tree, random forest, and multi-layer perceptron classifier. Tools and techniques broadly available to organizations and enthusiasts were used. Observations were made on working with network data in a machine learning context, strengths and weaknesses of different models on such data, and the overall efficacy of the tested models.  \nUltimately, it was found that simple models freely available to anyone can achieve high accuracy, recall, and F1 scores in network traffic classification, with the best-performing model, random forest, having 89% accuracy, a macro average F1 score of .77, and a macro average recall of 76%, with the most common feature of successful classification being related to maximum packet sizes in a network flow.  \nDegree Type  \nOpen Access Senior Honors Thesis  \nDepartment or School  \nCollege of Engineering and Technology  \nFirst Advisor  \nOmar Darwish, Ph. D.  \nSecond Advisor  \nJames M. Banfield, Ph. D.  \nThird Advisor  \nSean Che, Ph. D.  \nSubject Categories  \nInformation Security  \nThis open access senior honors thesis is available at DigitalCommons@EMU: [https://commons.emich.edu/honors/](https://commons.emich.edu/honors/)[ ](https://commons.emich.edu/honors/)785  \nFor Departmental & Highest Honors:  \nAPPLYING MACHINE LEARNING TO CATEGORIZE DISTINCT CATEGORIES OF  \nNETWORK TRAFFIC  \nBy  \nIsaac M. Dunham  \nA Senior Project Submitted to the  \nEastern Michigan University  \nHonors College  \nIn Partial Fulfillment of the Requirements for Graduation with Departmental Honors in Information Assurance & Cyber Defense  \nand with Highest Honors  \nApproved in Ypsilanti, MI on April 20, 2023  \nProject Advisor: Omar Darwish, Ph.D.  \nDepartmental Honors Advisor: James M. Banfield, Ph.D.  \nSchool Dir","cbCaicHS4o3aKNS4","https://ap.wps.com/l/cbCaicHS4o3aKNS4","pdf",1686723,1,67,"English","en",105,"# Abstract\n## Network traffic classification motivation\n## Data capture and feature creation\n## Model set and evaluation approach\n## Results and key findings","[{\"question\":\"为什么传统的网络流量分类方法会失效？\",\"answer\":\"传统方法依赖静态、预先编写的规则；当应用或底层协议发生变化（无论是合法还是非合法），这些规则容易失效。\"},{\"question\":\"研究如何为分类任务构建特征？\",\"answer\":\"先捕获并处理网络数据，再基于网络抓取得到流量（flow）相关的统计特征，并用于10个应用标签，覆盖视频会议、视频流、视频游戏和网页浏览等类别。\"},{\"question\":\"最好的模型是什么，取得了哪些关键指标？\",\"answer\":\"表现最佳的是随机森林模型，达到89%的准确率；宏平均F1为0.77，宏平均召回率为76%。同时，与成功分类相关的常见特征与网络流中的最大数据包大小有关。\"}]","Applying machine learning to categorize distinct categories of network traffic | PDF",1785720618,169,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"applying-machine-learning-to-categorize-distinct-categories-of-network-traffic","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/applying-machine-learning-to-categorize-distinct-categories-of-network-traffic/118852/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"为什么传统的网络流量分类方法会失效？","Question",{"text":75,"@type":76},"传统方法依赖静态、预先编写的规则；当应用或底层协议发生变化（无论是合法还是非合法），这些规则容易失效。","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"研究如何为分类任务构建特征？",{"text":80,"@type":76},"先捕获并处理网络数据，再基于网络抓取得到流量（flow）相关的统计特征，并用于10个应用标签，覆盖视频会议、视频流、视频游戏和网页浏览等类别。",{"name":82,"@type":73,"acceptedAnswer":83},"最好的模型是什么，取得了哪些关键指标？",{"text":84,"@type":76},"表现最佳的是随机森林模型，达到89%的准确率；宏平均F1为0.77，宏平均召回率为76%。同时，与成功分类相关的常见特征与网络流中的最大数据包大小有关。","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]