The ADS System for Real-Time Anomaly Detection with Scalable and SMART Monitoring in a Data Network
At a glance
- Citations
- 0
- References
- 6
- Comments
- 0
Öz
The This study presents an automated anomaly detection framework for analyzing cybersecurity datasets, focusing on network traffic and server performance logs. Using the Isolation Forest algorithm, we examined four datasets: a large-scale network traffic file (a01.dat with ~2.9M samples) and three server logs (cv_server_data.csv, gt_server_data.csv, and tr_server_data.csv). The goal was to identify irregular patterns indicative of cyber threats or system failures. Data preprocessing included normalization and missing-value imputation. The Isolation Forest model, configured with 200 estimators and 5% contamination, detected anomalies across all datasets. Results revealed 147,155 anomalies (4.98%) in a01.dat, while server logs showed 2.94–5.23% anomaly rates, with cv and tr datasets exhibiting higher outliers (5.23%) compared to gt (2.94%). Feature importance analysis highlighted key metrics (e.g., packet frequency, response times) correlated with anomalies. The framework achieved efficient processing, even for large datasets, with parallel task completion in <15 seconds for 200-tree ensembles. Visualizations (time-series and 2D scatter plots) demonstrated clear separation of anomalies. These findings suggest that lightweight unsupervised methods can effectively flag suspicious activity in heterogeneous IT infrastructure.
Publication details
- DOI
- 10.1109/ginotech63460.2025.11076977
- OpenAlex
- W4413068169
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Oturum Açın to join the discussion.