Network traffic anomaly detection plays an important role in improving cybersecurity by identifying unusual activities in network communication. This paper presents a machine learning-based system for detecting abnormal patterns in network traffic. The collected dataset is preprocessed to remove inconsistencies and prepare it for analysis, and Synthetic Minority Over-sampling Technique (SMOTE) is applied to balance the inherently imbalanced network traffic data and improve learning from minority attack samples. Both supervised and unsupervised machine learning algorithms, including Isolation Forest, Support Vector Machine, XGBoost, and LightGBM, are used to analyze network traffic and identify anomalies. The system is designed to detect suspicious activities such as cyber-attacks and abnormal traffic behaviour by learning patterns from network data, thereby improving the effectiveness and reliability of anomaly detection systems compared to traditional rule-based intrusion detection approaches.
Introduction
This work proposes a machine learning-based network traffic anomaly detection system to improve cybersecurity by identifying both known and unknown cyber-attacks. Traditional intrusion detection systems rely on predefined rules and signatures, making them ineffective against evolving threats such as DoS, DDoS, malware, and port scanning attacks. The proposed system addresses these limitations using a hybrid approach that combines Isolation Forest (unsupervised), XGBoost, and LightGBM (supervised) algorithms.
The system preprocesses network traffic data by removing missing values, duplicates, and irrelevant features, while SMOTE is used to balance imbalanced datasets and improve detection of minority attack classes. The models are trained and evaluated using standard metrics including accuracy, precision, recall, and F1-score, with the best-performing model selected for real-time anomaly detection.
Compared with existing systems, the proposed approach offers higher detection accuracy, lower false alarm rates, better handling of imbalanced data, and the ability to detect previously unseen attacks. A Flask-based web interface allows users to upload network traffic data and receive real-time predictions. The system is implemented in Python using libraries such as Scikit-learn, Pandas, NumPy, TensorFlow, and Matplotlib, and is designed to be scalable, reliable, and efficient for modern network security applications.
Conclusion
The proposed system detects network traffic anomalies using machine learning techniques to improve network security and identify potential cyber threats. By analyzing network traffic patterns, the system distinguishes between normal and abnormal activities, helping organizations monitor their networks and take preventive action. The system combines supervised and unsupervised machine learning models, and the use of ensemble learning techniques increases the reliability and stability of predictions by combining results from multiple models, reducing errors relative to a single-model approach.A key feature of the proposed system is the use of SMOTE to handle imbalanced datasets, since anomaly data is typically limited compared to normal traffic data; SMOTE helps balance the dataset by generating additional samples for the minority class, improving the learning ability of the models. The experimental results obtained on the implemented system demonstrate high detection accuracy and consistent precision, recall, and F1-score values, supporting the effectiveness of the approach. Overall, the system provides a reliable and efficient approach to improving network security and identifying cyber threats in a timely manner.
References
[1] U. Fiore, F. Palmieri, A. Castiglione, and A. De Santis, “Network anomaly detection with the restricted Boltzmann machine,” Neurocomputing, vol. 122, pp. 13–23, Dec. 2013.
[2] V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection,” ACM Comput. Surveys, vol. 41, no. 3, pp. 1–58, Jul. 2009.
[3] D. E. Difallah, P. Cudré-Mauroux, and S. A. McKenna, “Scalable anomaly detection for smart city infrastructure networks,” IEEE Internet Comput., vol. 17, no. 6, pp. 39–47, Nov. 2013.
[4] E. Anceaume et al., “Anomaly characterization in large scale networks,” in Proc. 44th Annu. IEEE/IFIP Int. Conf. Dependable Syst. Netw., Jun. 2014, pp. 68–79.
[5] M. Ahmed, A. N. Mahmood, and J. Hu, “A survey of network anomaly detection techniques,” J. Netw. Comput. Appl., vol. 60, pp. 19–31, Jan. 2016.
[6] M. Usama et al., “Unsupervised machine learning for networking: Techniques, applications and research challenges,” IEEE Access, vol. 7, pp. 65579–65615, 2019.
[7] K. Fotiadou et al., “Network traffic anomaly detection via deep learning,” Information, vol. 12, no. 5, p. 215, May 2021.
[8] M. A. Umer, K. N. Junejo, M. T. Jilani, and A. P. Mathur, “Machine learning for intrusion detection in industrial control systems: Applications, challenges, and recommendations,” Int. J. Crit. Infrastruct. Protection, vol. 38, Sep. 2022.
[9] A. A. Jihado and A. S. Girsang, “Hybrid deep learning network intrusion detection system based on convolutional neural network and bidirectional long short-term memory,” J. Adv. Inf. Technol., vol. 15, no. 2, pp. 219–232, 2024.
[10] S. Naseer et al., “Enhanced network anomaly detection based on deep neural networks,” IEEE Access, vol. 6, pp. 48231–48246, 2018.
[11] N. Kumar and S. Sharma, “A hybrid modified deep learning architecture for intrusion detection system with optimal feature selection,” Electronics, vol. 12, no. 19, p. 4050, Sep. 2023.
[12] ] S. Hajj et al., “Anomaly-based intrusion detection systems: The requirements, methods, measurements, and datasets,” Trans. Emerg. Telecommun. Technol., vol. 32, no. 4, p. e4240, Apr. 2021.
[13] S. Gunupusala and S. C. Kaila, “Multi-class network anomaly detection using machine learning techniques,” Contemp. Math., vol. 5, no. 2, pp. 5–22, Jun. 2024.
[14] V. Takale, A. Patil, A. Lonikar, A. Shinde, and P. V. Rupnar, “SecureNet: Network intrusion detection using machine learning and deep learning techniques,” Int. J. Res. Appl. Sci. Eng. Technol., vol. 12, no. 3, pp. 439–443, Apr. 2024.
[15] S. H. Rafique, A. Abdallah, N. S. Musa, and T. Murugan, “Machine learning and deep learning techniques for Internet of Things network anomaly detection—Current research trends,” Sensors, vol. 24, no. 6, p. 1968, Mar. 2024.
[16] M. Mynuddin et al., “Automatic network intrusion detection system using machine learning and deep learning,” in IEEE MTT-S Int. Microw. Symp. Dig., Feb. 2024, pp. 1–9.
[17] S. Ness, V. Eswarakrishnan, H. Sridharan, V. Shinde, and N. V. P. Janapareddy, “Anomaly detection in network traffic using advanced machine learning techniques,” IEEE Access, vol. 13, Dec. 2025.