[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125725-en":3,"doc-seo-125725-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125725,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","Use of Machine Learning Algorithms for Network Traffic Classification","Network threats using the network as an attack vector have increased in complexity, making signature-based IPS/IDS insufficient for many organizations. At the same time, corporate network traffic volumes are growing while quality-of-service constraints often limit deep inspection at the application layer. This work demonstrates that applying machine learning to network flow information enables effective detection of malicious traffic, developed within a software-defined networks paradigm using a CRISP-DM-based methodology.","Use of Machine Learning Algorithms for Network Traffic Classification  \nAdrin Nieto Antelo, Diego Fernndez Iglesias, and Francisco J. Nvoa Facultad de Inform´atica, Universidade da Coru~na, 15071, A Coru~na, Espa~na Centro de Investigaci´on CITIC, Departamento de Ciencias de la Computaci´on y  \nTecnolog´ıas de la Informaci´on, Universidade da Coru~na, 15071, A Coru~na, Espa~na Correspondence: [adrian.nieto1@udc.es](adrian.nieto1@udc.es)  \nDOI: [https://doi.org/10.17979/spudc.000024.48](https://doi.org/10.17979/spudc.000024.48)  \nAbstract: In recent years, the complexity of threats utilizing the network as an attack vector has significantly increased. Traditional attack prevention and detection systems (IPS/IDS) based on signatures do not provide an acceptable level of security for many organizations.  \nFurthermore, the volume of traffic on corporate networks has also grown exponentially, while quality of service requirements do not always allow for deep inspection (at the application layer) of packets.  \nThe main objective of this work is to demonstrate that the application of machine learning techniquesto the information of data flows circulating through the network allows for the satisfactory detection of malicious traffic. Specifically, this work is developed within an emerging network paradigm, such as software-defined networks.  \n1 Introduction  \nIt is of vital importance to offer the highest possible protection to defend ourselves against all the current computer threats. Currently, our protection mainly relies on methods based on policies and rules. These methods have certain issues, such as human errors in rule configuration, response time to threats, and adaptability. That’s why Artificial Intelligence, especially Machine Learning, is gaining more weight in cybersecurity.  \nThis work aims to compare and understand different machine learning techniques used in the classification of network traffic on an SDN (Software-Defined Network) . To achieve this, a methodology known as CRISP-DM (Cross-Industry Standard Process for Data Mining) has been employed Wirth and Hipp (2000) . This article will be structured according to this methodology, with each section representing a different step in it. However, for this article, the business understanding section has been omitted, as it involves the theoretical explanation of the concepts that will be used throughout the work.  \n2 Understanding the data  \nThis phase involves the collection, description, exploration, and verification of the data to be used.  \nThe dataset used is one that already existed previously and was not generated specifically for this work, as creating a dataset is not one of the objectives of this project. In this case, the InSDN dataset Elsayed et al. (2020) is used.  \nThis dataset presents various attack scenarios from different sources, both external and internal, that can affect an SDN network. It includes various attack scenarios, such as DoS attacks,  \n322 Proceedings XoveTIC 2023  \nDDoS attacks, password guessing attacks, web application attacks, probe attacks, botnet attacks, and U2R attacks. The dataset is divided into three groups based on the type of traffic and target machines. The first group includes normal traffic. The second group includes attacks targeted at the Metasploitable2 server, which is a virtual machine server. The third group consists of attacks on the OVS machine, which is a switch.  \nAfter loading the dataset, exploration is conducted using a Pandas dataframe specifically created to work with this data. Among these explorations, the correlation matrix stands out, which will be used in the next step.  \n3 Data preparation  \nIn this phase, the selection of features and samples to be used in the Machine Learning algorithm will be carried out. The quality of the data will be checked, formatted, modified, or new data will be created as necessary.  \nThe data from the previous dataset are not in an appropriate format for training, so they","cbCaipJ5TcKrwG85","https://ap.wps.com/l/cbCaipJ5TcKrwG85","pdf",80261,1,5,"English","en",105,"# Introduction\n# Understanding the data\n## Dataset description\n## Data exploration\n# Data preparation\n## Outlier removal\n## Feature engineering and formatting\n## Standardization and data selection","[{\"question\":\"Why are traditional signature-based IPS/IDS systems insufficient for network security?\",\"answer\":\"Signature-based systems do not provide an acceptable security level for many organizations, especially as threat complexity and attack patterns evolve.\"},{\"question\":\"What is the main objective of the work in network traffic classification?\",\"answer\":\"To show that machine learning applied to network flow data can satisfactorily detect malicious traffic.\"},{\"question\":\"How does the methodology support the machine learning workflow in this study?\",\"answer\":\"The study uses CRISP-DM, structuring the article so each section corresponds to a step in the process, with the business understanding step omitted.\"}]","Use of Machine Learning Algorithms for Network Traffic Classification | PDF",1785900863,13,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"use-of-machine-learning-algorithms-for-network-traffic-classification","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/use-of-machine-learning-algorithms-for-network-traffic-classification/125725/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are traditional signature-based IPS/IDS systems insufficient for network security?","Question",{"text":75,"@type":76},"Signature-based systems do not provide an acceptable security level for many organizations, especially as threat complexity and attack patterns evolve.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the main objective of the work in network traffic classification?",{"text":80,"@type":76},"To show that machine learning applied to network flow data can satisfactorily detect malicious traffic.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the methodology support the machine learning workflow in this study?",{"text":84,"@type":76},"The study uses CRISP-DM, structuring the article so each section corresponds to a step in the process, with the business understanding step omitted.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":21,"slug":137},19,"General","general"]