[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117100-en":3,"doc-seo-117100-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117100,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","Network Anomaly Detection Using Machine Learning - Thesis","The growing volume and sophistication of network attacks in digital environments create major risks to system security and operational continuity. Anomaly detection is essential for spotting previously unseen attacks and suspicious behavior that evade traditional signatures. This thesis applies machine learning methods to build an effective, efficient network anomaly detection system. Multiple models are evaluated, and a novel framework based on Autoencoders is proposed to strengthen detection performance and improve robustness.","DEPARTMENT OF INFORMATION ENGINEERING  \nMASTER DEGREE IN ICT FOR INTERNET AND MULTIMEDIA  \nNETWORK ANOMALY DETECTION USING MACHINE LEARNING  \nSupervisor: Prof. Nicola Laurenti  \nCo-supervisor: Prof. Stefano Tomasin  \nInternship supervisor: Antonios Atlasis  \nCandidate: Stefano Leggio  \nACADEMIC YEAR: 2022-2023  \nGraduation date: 30/11/2023  \nAbstract  \nThe constant increase of network attacks in the digital world creates a significant threat to system security and availability. Anomaly detection plays a crucial role in identifying previously unknown network attacks and potential malicious activities. This thesis focuses on leveraging machine learning techniques for effective network anomaly detection to enhance cybersecurity measures. The study explores various machine learning models to develop a robust and efficient anomaly detection system. At the end of the research, a novel framework based on Autoencoders (AE) is proposed to further enhance the detection capabilities.  \nContents  \n1 Introduction 11  \n1.1 Context .............................................. 12  \n1.2 Objectives ............................................. 12  \n1.3 Structure ............................................. 13  \n2 Background theory 15  \n2.1 Intusion detection systems .................................... 16  \n2.1.1 Network and host based IDSs .............................. 16  \n2.1.2 Signature based IDSs .................................. 17  \n2.1.3 Anomaly based IDSs ................................... 18  \n2.2 Machine learning ......................................... 19  \n2.2.1 Paradigms ......................................... 21  \n2.2.2 Binary classification ................................... 22  \n2.2.3 Metrics .......................................... 22  \n2.2.4 k-means clustering .................................... 24  \n2.2.5 Random forest ...................................... 25  \n2.2.6 Multi layer perceptron .................................. 26  \n2.2.7 Convolutional neural networks ............................. 28  \n2.2.8 Autoencoder ....................................... 29  \n2.2.9 Long short time memory ................................. 30  \n2.3 Network anomaly detection using machine learning ...................... 32  \n2.3.1 Network flow ....................................... 33  \n2.3.2 Challenges ........................................ 34  \n2.3.3 Literature review ..................................... 35  \n2.4 Summary ............................................. 38  \n3 Methodology 39  \n3.1 Tools ................................................ 40  \n3.2 Dataset .............................................. 41  \n3.2.1 CIC-IDS2017 ....................................... 42  \n3.2.2 NSL-KDD ......................................... 44  \n3.2.3 Comparison ........................................ 46  \n3.3 Preprocessing ........................................... 47  \n3.3.1 Cleaning .......................................... 47  \n3.3.2 Numericalization ..................................... 47  \n3.3.3 Normalization ....................................... 47  \n3.4 Feature selection ......................................... 48  \n3.4.1 Filter methods ...................................... 48  \n3.4.2 Wrapper methods .................................... 49  \n3.4.3 Embedded methods ................................... 49  \n3.5 Model ............................................... 50  \n3.5.1 Evaluation ........................................ 51  \n3.6 Summary ............................................. 52  \n4 Results 53  \n4.1 Feature selection ......................................... 54  \n4.1.1 Pearson correlation .................................... 54  \n4.1.2 XGBoost ......................................... 55  \n4.1.3 Considerations ...................................... 56  \n4.2 k-means clustering ........................................ 58  \n4.2.1 CIC-IDS2017 ....................................... 58  \n4.2.2 NSL-KDD ...........","cbCaiuAOHtFDY9Ox","https://ap.wps.com/l/cbCaiuAOHtFDY9Ox","pdf",2979615,1,93,"English","en",105,"# Introduction\n## Context\n## Objectives\n## Structure\n# Background theory\n## Intusion detection systems\n## Machine learning\n## Network anomaly detection using machine learning\n## Summary\n# Methodology\n## Tools\n## Dataset\n## Preprocessing\n## Feature selection\n## Model\n## Evaluation\n## Summary\n# Results\n## Feature selection\n## k-means clustering\n## Random forest\n## Multi layer perceptron\n## Convolutional neural networks\n## Autoencoder\n## Long short time memory\n## Comparison\n## Proposed framework\n## Summary\n# Conclusions\n## Key findings\n## Limitations\n## Future works\n## Final comment\n# Bibliography","[{\"question\":\"Why is anomaly detection important for network security?\",\"answer\":\"It identifies previously unknown network attacks and potential malicious activities that are not captured by traditional detection approaches.\"},{\"question\":\"Which machine learning models are investigated in the thesis?\",\"answer\":\"The study explores models including k-means clustering, random forest, multi layer perceptron, convolutional neural networks, autoencoders, and long short time memory.\"},{\"question\":\"What novel contribution does the research propose?\",\"answer\":\"A new framework based on Autoencoders (AE) is introduced to enhance the system’s detection capabilities, including design steps such as outlier removal and threshold estimation.\"}]","Network Anomaly Detection Using Machine Learning - Thesis | PDF",1785673736,234,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"network-anomaly-detection-using-machine-learning-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/network-anomaly-detection-using-machine-learning-thesis/117100/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is anomaly detection important for network security?","Question",{"text":75,"@type":76},"It identifies previously unknown network attacks and potential malicious activities that are not captured by traditional detection approaches.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which machine learning models are investigated in the thesis?",{"text":80,"@type":76},"The study explores models including k-means clustering, random forest, multi layer perceptron, convolutional neural networks, autoencoders, and long short time memory.",{"name":82,"@type":73,"acceptedAnswer":83},"What novel contribution does the research propose?",{"text":84,"@type":76},"A new framework based on Autoencoders (AE) is introduced to enhance the system’s detection capabilities, including design steps such as outlier removal and threshold estimation.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]