[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126278-en":3,"doc-seo-126278-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126278,2336475104736,"Quinn","https://ap-avatar.wpscdn.com/avatar/22000c4c5e0e5b17e70?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786591360781797222",8,"Research & Report","Mitigating Online Banking Fraud Using Machine Learning and Anomaly Detection","Online banking fraud has become increasingly prevalent as digital financial services expand, requiring security approaches that can identify both known and emerging threats. This paper proposes a machine-learning framework that combines anomaly detection with network packet analysis, with emphasis on DDoS attacks. An ensemble model using Isolation Forest and K-means delivers 98% accuracy and 98% F1-score, lowering false positives to 2%. Its semi-supervised design supports zero-day detection without labeled attack data, using feature optimization and real-time processing. Results indicate strong suitability for integration into banking security systems.","Journal of Information Systems and Informatics  \nVol. 7, No. 2, June 2025 e-ISSN: 2656-4882 p-ISSN: 2656-5935  \nDOI: 10.51519/journalisi.v7i2.1076 Published By DRPM-UBD  \nMitigating Online Banking Fraud Using Machine Learning and Anomaly Detection  \nCaden Dobson1, Sheunesu Makura2, Seani Rananga3  \n1,2,3Department of Computer Science, University of Pretoria, Pretoria, South Africa  \n1,2Digital Forensic science Research Group  \n3Data Science for Social Impact Research Group  \n[Email:](Email:1 u21612073@tuks.co.za)[1](Email:1 u21612073@tuks.co.za)[ u21612073@tuks.co.za](Email:1 u21612073@tuks.co.za), [2](2 makura.sm@up.ac.za)[ makura.sm@up.ac.za](2 makura.sm@up.ac.za), [3](3 seani.rananga@up.ac.za)[ seani.rananga@up.ac.za](3 seani.rananga@up.ac.za)  \nAbstract  \nOnline banking fraud has become increasingly prevalent with the widespread adoption of digital financial services, necessitating advanced security solutions capable of detecting both known and emerging threats. This paper presents a robust machine learning framework that integrates anomaly detection with network packet analysis to mitigate fraudulent activities, focusing particularly on Distributed Denial of Service (DDoS) attacks. The key contribution is an ensemble model combining Isolation Forest and K-means clustering, which achieves 98% accuracy and 98% F1-score in anomaly detection while reducing false positives to 2% which is a critical improvement for operational deployment in banking systems. The framework’s semi-supervised architecture enables zero-day fraud detection without reliance on labeled attack data, addressing a fundamental limitation of signature-based systems. By leveraging feature optimization (PCA/t-SNE) and real-time processing capabilities, this solution offers financial institutions a practical, adaptive defense mechanism against evolving cyber threats. The results demonstrate significant potential for integration into existing banking security infrastructures to enhance fraud prevention with minimal disruption.  \nKeywords: Machine Learning; Fraud Mitigation; Banking; Anomaly Detection; Network Packets, Fraud Detection.  \n1. INTRODUCTION  \nThe use of the internet has grown exponentially since its inception, with over half of the world’s population using the internet in 2017 [1] .This growing reliance on digital platforms to complete everyday tasks has resulted in a significant increase in cybercrime, particularly within financial systems. Online banking allows users to perform daily banking activities over the internet via web or mobile applications. While this service provides convenience, it also introduces vulnerabilities that can be exploited by cybercriminals. As the financial sector becomes increasingly digitized, the need for effective and intelligent security solutions becomes more critical to mitigate the risk of fraud and ensure consumer trust. Recent attacks on  \n1153  \nThis work is licensed under a Creative Commons Attribution 4.0 International License.  \np-ISSN: 2656-5935 [http://journal-isi.org/index.php/isi](http://journal-isi.org/index.php/isi) e-ISSN: 2656-4882  \nmajor banks, such as the 2023 DDoS campaign against South African financial institutions [2] and the sophisticated fraud schemes targeting EU digital payment systems [3] , demonstrate the evolving threat landscape. These incidents highlight the critical need for advanced security solutions that can adapt to both known and emerging attack vectors.  \nA key technology for monitoring and protecting such systems is intrusion detection, which identifies abnormal activity in network traffic. Traditional misuse detection techniques rely on identifying known attack signatures embedded within network packets or audit trails [4] . However, such systems are often limited to detecting only previously observed attacks. For them to remain effective, their signature databases must be frequently updated [5] .Moreover, these techniques are ineffective against zero-day attacks and attack v","cbCaigSiAhIqoMsi","https://ap.wps.com/l/cbCaigSiAhIqoMsi","pdf",4839400,7,1,31,"English","en",105,"# Introduction\n## Online banking threats and evolving cybercrime\n## Intrusion detection and limitations of signature-based methods\n## Anomaly detection and role of machine learning\n## Semi-supervised learning for zero-day fraud detection\n## Research focus and objectives","[{\"question\":\"What problem does the paper address in online banking security?\",\"answer\":\"It addresses the growing risk of online banking fraud and evolving cyber threats, especially attacks such as DDoS that require adaptive detection beyond known signatures.\"},{\"question\":\"How does the proposed system detect anomalies and fraudulent activity?\",\"answer\":\"It integrates network packet analysis with a machine-learning anomaly detection framework, using an ensemble approach that combines Isolation Forest and K-means clustering.\"},{\"question\":\"Why is semi-supervised learning important for zero-day fraud detection?\",\"answer\":\"The semi-supervised architecture trains with a small labeled set and a larger unlabeled set, enabling detection of novel anomalies without relying on labeled attack data and reducing false positives.\"}]","Mitigating Online Banking Fraud Using Machine Learning and Anomaly Detection | PDF",1785904225,78,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"mitigating-online-banking-fraud-using-machine-learning-and-anomaly-detection","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/mitigating-online-banking-fraud-using-machine-learning-and-anomaly-detection/126278/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"What problem does the paper address in online banking security?","Question",{"text":77,"@type":78},"It addresses the growing risk of online banking fraud and evolving cyber threats, especially attacks such as DDoS that require adaptive detection beyond known signatures.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"How does the proposed system detect anomalies and fraudulent activity?",{"text":82,"@type":78},"It integrates network packet analysis with a machine-learning anomaly detection framework, using an ensemble approach that combines Isolation Forest and K-means clustering.",{"name":84,"@type":75,"acceptedAnswer":85},"Why is semi-supervised learning important for zero-day fraud detection?",{"text":86,"@type":78},"The semi-supervised architecture trains with a small labeled set and a larger unlabeled set, enabling detection of novel anomalies without relying on labeled attack data and reducing false positives.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,112,117,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":110,"slug":111},5,"Comic",60,"comic",{"id":113,"doc_module":4,"doc_module_name":47,"category_name":114,"show_sort_weight":115,"slug":116},6,"Technology",50,"technology",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":108,"slug":139},19,"General","general"]