[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118404-en":3,"doc-seo-118404-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118404,1099514067438,"River Wang","https://ap-avatar.wpscdn.com/avatar/100002539ee87300030?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780474512215547542",8,"Research & Report","Identifying the Origin of Cyber Attacks Using Machine Learning and Network Traffic Analysis","Cyber attacks such as phishing, junk emails, and keylogging require accurate attribution of their origin to enable timely defense and mitigation. This paper presents a machine-learning approach for identifying data provenance from network traffic, framing the problem around supervised learning and network intrusion detection. It leverages PCAP-derived features including IP addresses, packet lengths, and protocol types, using a Random Forest classifier to classify attack behaviors. Experiments validate the method and assess model efficiency and precision for real-world applicability.","Identifying the Origin of Cyber Attacks Using Machine Learning and Network Traffic Analysis  \nTianqing Du  \nTeda International School No. 72, 300457 3rd Avenue Teda Tianjin, China  \nAbstract. In this paper, PCAP refers to Packet Capture, Network Intrusion Detection Systems refers to NIDS, Artificial Intelligence refers to AI, machine learning refers to ML, Computer Vision refers to CV, and Natural Language Processing refers to NLP. While the development of the internet promotes global progress, it also brings various cyber-attacks, such as phishing, junk emails, and keylogging. To ensure a clean internet environment, it is essential to identify the origin of cyber-attacks for effective defense and mitigation. This paper introduces an effective method of internet protection—machine learning. A common technique in the modern world, machine learning offers significant insights into locating the IP address and data origin. The focus of this paper is on how supervised machine learning is used to determine the data origin. The Random Forest Classifier is the key model analyzing network traffic data to predict the origin of cyber-attacks. By converting IP addresses, packet lengths, and protocol types into numerical features from PCAP files, this study applies machine learning techniques to classify attack behaviors. Additionally, an experiment testing the model's effectiveness is designed to prove its efficiency and ensure the model's precision.  \n1 Introduction  \nWith the rapid development of 5G, the internet, IoT, and cloud computing, network complexity and traffic volume have increased significantly, leading to a rise in sophisticated cyber-attacks. These advancements pose significant challenges to internet environments and cybersecurity. Therefore, effective detection and response are crucial. NIDS, a second line of defense behind firewalls, plays an important role in identifying malicious attacks on the internet and providing real-time monitoring and protection.  \nAround 1980, James Anderson first introduced the concept of intrusion detection, although it was initially constrained by limited computing resources. However, recent advancements in computing power and AI have enabled the application of machine learning (ML) methods to network security [1, 2]. Various studies have demonstrated the effectiveness of ML in identifying different types of cyber-attacks [3-5] . Despite this progress, the imbalance between normal and malicious traffic data presents a significant challenge since most network traffic is benign, making it difficult for ML models to accurately detect rare attacks [3, 5] . Deep learning, a subfield of ML, has shown remarkable success in fields like  \nCorresponding author: [andrew2902@tedais.net](andrew2902@tedais.net)  \n© The Authors, published by EDP Sciences. This is an open access article distributed under the terms of the Creative Commons Attribution License 4.0 ([https://creativecommons.org/licenses/by/4.0/](https://creativecommons.org/licenses/by/4.0/)).  \ncomputer vision (CV) and natural language processing (NLP), and its application to intrusion detection is gaining momentum [2 , 4] . Deep learning models can extract high-dimensional data features and convert anomaly detection into a classification problem, improving realtime processing capabilities [1, 2]. However, the imbalance in network traffic data remains a challenge. To address this, the Difficult Set Sampling Technique (DSSTE) is proposed to handle class imbalance in network traffic data. This novel algorithm reduces the number of majority class samples and augments minority class samples, improving classifier performance. Researchers validate the approach using classic and contemporary datasets, such as NSL-KDD and CSE-CIC-IDS2018, and evaluate several ML and deep learning algorithms, including Random Forest, Support Vector Machine, XGBoost, Long Short-Term Memory (LSTM), AlexNet, and Mini-VGGNet [6-10] .  \n2 Methodology  \nThe overall data set wa","cbCaitw760yRyYdZ","https://ap.wps.com/l/cbCaitw760yRyYdZ","pdf",299683,1,6,"English","en",105,"# Introduction\n# Methodology\n## Data Collection\n## Feature Extraction\n## Data Preprocessing","[{\"question\":\"Why is identifying the origin of cyber attacks important?\",\"answer\":\"Attribution supports effective defense and mitigation by enabling cleaner and safer internet operations. Accurate origin detection helps respond to malicious activity more reliably.\"},{\"question\":\"What machine learning model is used to analyze network traffic?\",\"answer\":\"The Random Forest Classifier is used to analyze network traffic data and predict the origin of cyber attacks.\"},{\"question\":\"Which features are extracted from PCAP files for training?\",\"answer\":\"The method extracts source IP address, destination IP address, protocol type, and packet length from PCAP data to form numerical inputs for classification.\"}]","Identifying the Origin of Cyber Attacks Using Machine Learning and Network Traffic Analysis | PDF",1785683454,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"identifying-the-origin-of-cyber-attacks-using-machine-learning-and-network-traffic-analysis","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/identifying-the-origin-of-cyber-attacks-using-machine-learning-and-network-traffic-analysis/118404/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is identifying the origin of cyber attacks important?","Question",{"text":76,"@type":77},"Attribution supports effective defense and mitigation by enabling cleaner and safer internet operations. Accurate origin detection helps respond to malicious activity more reliably.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What machine learning model is used to analyze network traffic?",{"text":81,"@type":77},"The Random Forest Classifier is used to analyze network traffic data and predict the origin of cyber attacks.",{"name":83,"@type":74,"acceptedAnswer":84},"Which features are extracted from PCAP files for training?",{"text":85,"@type":77},"The method extracts source IP address, destination IP address, protocol type, and packet length from PCAP data to form numerical inputs for classification.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]