Multi-Type Anomaly Detection Based on Raw Network Traffic

In this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively.

Paper

Full text

PDF

Multi-Type Anomaly Detection Based on Raw Network Traffic

Semantic Scholar · Computer Science · 2021

Abstract

In this article, we presented a visualization method for representing network traffic features using raw data of it. The raw network traffic data was divided into regulated segments. By employing a supervised neural network and an expert-knowledge based labeling method, model training was conducted based on a dataset covering two weeks' network traffic, where the first week's data was employed as the training set and the second week's data was used as the validation set. At last, we achieved validation precision scores of 0.980 for detecting the ARP flooding, 0.800 and 0.815 for detecting the malicious SMB and TCP SYN flooding respectively.

Similar papers

© 2026 NYSGPT2525 LLC