conference-paper

The ADS System for Real-Time Anomaly Detection with Scalable and SMART Monitoring in a Data Network

Research footprint

At a glance

Citations
0
References
6
Comments
0
Paper overview

Abstract

The This study presents an automated anomaly detection framework for analyzing cybersecurity datasets, focusing on network traffic and server performance logs. Using the Isolation Forest algorithm, we examined four datasets: a large-scale network traffic file (a01.dat with ~2.9M samples) and three server logs (cv_server_data.csv, gt_server_data.csv, and tr_server_data.csv). The goal was to identify irregular patterns indicative of cyber threats or system failures. Data preprocessing included normalization and missing-value imputation. The Isolation Forest model, configured with 200 estimators and 5% contamination, detected anomalies across all datasets. Results revealed 147,155 anomalies (4.98%) in a01.dat, while server logs showed 2.94–5.23% anomaly rates, with cv and tr datasets exhibiting higher outliers (5.23%) compared to gt (2.94%). Feature importance analysis highlighted key metrics (e.g., packet frequency, response times) correlated with anomalies. The framework achieved efficient processing, even for large datasets, with parallel task completion in <15 seconds for 200-tree ensembles. Visualizations (time-series and 2D scatter plots) demonstrated clear separation of anomalies. These findings suggest that lightweight unsupervised methods can effectively flag suspicious activity in heterogeneous IT infrastructure.

Record transparency

Publication details

DOI
10.1109/ginotech63460.2025.11076977
OpenAlex
W4413068169
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.