[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122919-en":3,"doc-seo-122919-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122919,137441390410,"Hazel","https://ap-avatar.wpscdn.com/avatar/2000252f4ab5702993?_k=1776741390130283984",8,"Research & Report","Detecting anomalies in network traffic using machine learning techniques","The document addresses anomaly detection in network traffic using machine learning and neural network methods. Logistic regression, support vector machines, random forests, gradient boosting, and fully connected networks, together with recurrent LSTM models, are evaluated as classification approaches. It includes grid search for optimal parameters via cross-validation and proposes feature selection using L1-regularized logistic regression plus mutual-information-based selection for categorical features. One-class methods such as One-Class SVM, Isolation Forest, Local Outlier Factor, and Elliptic Envelope are also applied, including ensemble stacking, while algorithm efficiency is analyzed.","Detecting anomalies in network traffic using machine learning techniques  \nTuleubay Safiullin  \nDepartment of Mathematical Modelling and Data Analysis Belarusian State University Minsk, Belarus [tuleubay.safiullin@mail.ru](tuleubay.safiullin@mail.ru)  \nAbramovich Michael Department of Mathematical Modelling and Data Analysis Belarusian State University Minsk, Belarus [AbramovichMS@bsu.by](AbramovichMS@bsu.by)  \nAbstract—The problem of anomaly detection in network traffic using machine learning and neural network methods is considered. Logistic regression, support vector method, random forest, gradient boosting, fully connected neural network andrecurrent LSTM neural network were used as classification models for anomaly detection. A grid search for optimal parameters on cross-validation of these models was carried out. The architectures of the fully connected and recurrent LSTM neural network were developed. One-Class SVM, isolation Forest, Local Outlier Factor, Elliptic Envelope methods of oneclass classification were also applied. The application of ensembles of classifiers for detection of anomalous traffic, in particular, built using the stacking procedure, is considered. The efficiency of all algorithms is analysed.  \nKeywords—anomaly detection; machine learning; neural networks  \nI. DESCRIPTION OF THE TEST DATA SET  \nThe NSL-KDD dataset [1] was used for software testing. This dataset stands as an industry standard, renowned for its effectiveness in assessing the performance of adaptive algorithms across a spectrum of network protocols, including TCP, UDP, and ICMP.  \nTo provide a comprehensive understanding of the dataset's composition and attributes, we relied on the detailed information presented in [2] . This valuable resource furnished us with a comprehensive catalogue of attributes, complete with their corresponding variable types and the range of possible values. There are 43 features in total, including the target variable.  \nThe training dataset contains 125,973 observations. The test dataset contains 22,544 observations. A noteworthy aspect of the NSL-KDD dataset that bolstered the robustness of our testing was its balanced nature. This equilibrium was reflected in the training dataset, which harboured 67,343 representatives of legitimate traffic and 58,630 representatives of anomalous traffic. This balanced distribution ensured that our software was rigorously tested against both normal and anomalous network activities, enhancing its adaptability and effectiveness.  \nAs we delved into the realm of feature selection, a meticulous approach was employed to identify the most informative attributes among the dataset's numerical features. Leveraging the power of L1-regularized logistic regression, a cutting-edge technique in feature selection, we carefully curated a subset of 15 features. This judicious selection process was undertaken to optimize our software's performance and ensure it focused on the most relevant aspects of the data.  \nTo ensure the robustness and consistency of our data preprocessing pipeline, an additional step was taken to further normalize the traits. This meticulous process involved the  \napplication of the MinMaxScaler, an essential component from the vast arsenal of tools offered by the scikit-learn library. MinMaxScaler transforms the numerical feature X by the formula:  \n(x − Xmin) 􀀒 ( Xmax − Xmin) (􀀔)  \nwhere Xmin, Xmax–the highest and the lowest value of the trait, respectively.  \nThus, the numerical feature will take values on the interval [0, 1] .  \nFrom the categorical features, 30 informative features were selected using the mutual information criterion [3] . Thus, the total number of informative features was 45.  \nII. ANOMALOUS TRAFFIC DETECTION USING CLASSIFICATION  \nMETHODS AND NEURAL NETWORKS  \nLogistic regression, support vector method, random forest, gradient boosting, fully connected neural network andrecurrent LSTM neural network were used as classification models. A cross-v","cbCaihJ8WcmnpajJ","https://ap.wps.com/l/cbCaihJ8WcmnpajJ","pdf",189030,1,4,"English","en",105,"# Description of the test data set\n## Dataset overview (NSL-KDD)\n## Feature selection and preprocessing\n# Anomalous traffic detection using classification methods and neural networks\n## Classification models and cross-validation\n## Neural network architectures (fully connected, LSTM)\n## Performance results","[{\"question\":\"Which supervised classification models are used for detecting anomalous traffic?\",\"answer\":\"The document evaluates logistic regression, support vector methods, random forest, gradient boosting, and fully connected neural networks, along with recurrent LSTM neural networks. Model parameters are optimized via grid search with cross-validation.\"},{\"question\":\"How is the dataset prepared and features selected before training?\",\"answer\":\"NSL-KDD is used, with 43 total features. Numerical features are reduced using L1-regularized logistic regression to select 15 features, while categorical features are further selected using mutual information, yielding 45 informative features in total. Numerical values are normalized using MinMaxScaler.\"},{\"question\":\"What unsupervised or one-class methods are applied besides supervised learning?\",\"answer\":\"One-class classification methods include One-Class SVM, Isolation Forest, Local Outlier Factor, and Elliptic Envelope. The document also considers ensemble detection using stacking for anomalous traffic detection.\"}]","Detecting anomalies in network traffic using machine learning techniques | PDF",1785813670,10,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-anomalies-in-network-traffic-using-machine-learning-techniques","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":21},"https://docshare.wps.com/document/detecting-anomalies-in-network-traffic-using-machine-learning-techniques/122919/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-05","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Which supervised classification models are used for detecting anomalous traffic?","Question",{"text":75,"@type":76},"The document evaluates logistic regression, support vector methods, random forest, gradient boosting, and fully connected neural networks, along with recurrent LSTM neural networks. Model parameters are optimized via grid search with cross-validation.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the dataset prepared and features selected before training?",{"text":80,"@type":76},"NSL-KDD is used, with 43 total features. Numerical features are reduced using L1-regularized logistic regression to select 15 features, while categorical features are further selected using mutual information, yielding 45 informative features in total. Numerical values are normalized using MinMaxScaler.",{"name":82,"@type":73,"acceptedAnswer":83},"What unsupervised or one-class methods are applied besides supervised learning?",{"text":84,"@type":76},"One-class classification methods include One-Class SVM, Isolation Forest, Local Outlier Factor, and Elliptic Envelope. The document also considers ensemble detection using stacking for anomalous traffic detection.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":29,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]