Anomaly detection in network flows using unsupervised online machine learning
Miguel-Diez, Alberto, Campazas-Vega, Adrián, Guerrero-Higueras, Ángel Manuel, Álvarez-Aparicio, Claudia, Matellán-Olivera, Vicente
–arXiv.org Artificial Intelligence
Nowadays, the volume of network traffic continues to grow, along with the frequency and sophistication of attacks. This scenario highlights the need for solutions capable of continuously adapting, since network behavior is dynamic and changes over time. This work presents an anomaly detection model for network flows using unsupervised machine learning with online learning capabilities. This approach allows the system to dynamically learn the normal behavior of the network and detect deviations without requiring labeled data, which is particularly useful in real-world environments where traffic is constantly changing and labeled data is scarce. The model was implemented using the River library with a One-Class SVM and evaluated on the NF-UNSW-NB15 dataset and its extended version v2, which contain network flows labeled with different attack categories. The results show an accuracy above 98%, a false positive rate below 3.1%, and a recall of 100% in the most advanced version of the dataset. In addition, the low processing time per flow (<0.033 ms) demonstrates the feasibility of the approach for real-time applications.
arXiv.org Artificial Intelligence
Sep-3-2025
- Country:
- Asia
- Japan > Honshū
- Kansai > Osaka Prefecture > Osaka (0.04)
- Singapore > Central Region
- Singapore (0.04)
- Thailand (0.04)
- Japan > Honshū
- Europe
- Belgium > Flanders
- West Flanders > Bruges (0.04)
- Czechia (0.04)
- France (0.04)
- Portugal
- Serbia > Central Serbia
- Belgrade (0.04)
- Spain
- Castile and León > León Province
- León (0.04)
- Valencian Community > Valencia Province
- Valencia (0.04)
- Castile and León > León Province
- Switzerland > Vaud
- Lausanne (0.04)
- United Kingdom > England
- Oxfordshire > Oxford (0.04)
- Belgium > Flanders
- North America
- Canada > Ontario
- National Capital Region > Ottawa (0.04)
- United States
- California > San Diego County
- San Diego (0.04)
- Massachusetts > Middlesex County
- Cambridge (0.04)
- California > San Diego County
- Canada > Ontario
- Oceania > Australia
- Australian Capital Territory > Canberra (0.04)
- New South Wales > Sydney (0.04)
- Asia
- Genre:
- Research Report > New Finding (0.87)
- Industry:
- Education (0.90)
- Government > Military (1.00)
- Information Technology > Security & Privacy (1.00)
- Technology: