Improving Network Anomaly Detection Using Packet Symmetry Analysis with Machine Learning and Deep Learning Algorithms
Open Access DepositedThis praxis combines packet symmetry analysis with machine learning models and deep learning models to make improvements to current Intrusion Detection Systems (IDS). Today’s methods are inadequate for capturing advanced cyber threats, such as zero-day and advanced persistent threats. By using some asymmetry metrics, for example, a difference in packet counts, sizes, and inter-arrival times between forward and backward network flows, this praxis presents analysis that includes the training and validation of various machine learning and deep learning algorithms, such as XGBoost, Random Forest, Decision Trees, Extra Trees, Deep Neural Networks, Deep Belief Networks, Long Short-Term Memory Networks, and hybrid variations of them on created symmetry features. These models achieve detection accuracy in machine learning with a mean of 99.23%. For deep learning, the average accuracy was 99.30%. This praxis demonstrates improved detection accuracy, a reduced false positive rate, and intelligibility along with interpretability through plot analysis using Partial Dependence and Kernel Density Estimation plots. The method can be used on IDS detectors as well as on Internet of Things (IoT) systems and large network infrastructures.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.