Anomaly Detection Module for Network Traffic Monitoring in Public Institutions

Sensors (Basel). 2023 Mar 9;23(6):2974. doi: 10.3390/s23062974.

Abstract

It seems to be a truism to say that we should pay more and more attention to network traffic safety. Such a goal may be achieved with many different approaches. In this paper, we put our attention on the increase in network traffic safety based on the continuous monitoring of network traffic statistics and detecting possible anomalies in the network traffic description. The developed solution, called the anomaly detection module, is mostly dedicated to public institutions as the additional component of the network security services. Despite the use of well-known anomaly detection methods, the novelty of the module is based on providing an exhaustive strategy of selecting the best combination of models as well as tuning the models in a much faster offline mode. It is worth emphasizing that combined models were able to achieve 100% balanced accuracy level of specific attack detection.

Keywords: anomaly detection; cybersecurity; network traffic monitoring.

Grants and funding

The work was partially financed within the statutory research project of ITI EMAG (Łukasiewicz Research Network) and partially from the statutory funds of the Wroclaw Centre for Networking and Supercomputing, Wroclaw University of Science and Technology, Wroclaw, Poland.