In this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively.
Paper
Full text
Multi-Type Anomaly Detection Based on Raw Network Traffic
Semantic Scholar · Computer Science · 2021
Abstract
In this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively.