ADVANCED ANOMALY DETECTION IN NETWORK TRAFFIC USING ENSEMBLE MACHINE LEARNING

The proposed system is a web-based network traffic anomaly detection framework designed to identify unusual or potentially malicious network activities in real time. The system uses the Isolation Forest algorithm, an unsupervised machine learning technique that detects anomalous observations in high-dimensional datasets without requiring predefined normal traffic labels.The framework is implemented using Flask as the web application backend. Users can upload network traffic data in CSV format, after which the system performs automated preprocessing and anomaly detection. The preprocessing stage includes handling missing values, standardizing numerical features, and validating relevant data parameters to improve the reliability of the detection process. After preprocessing, the Isolation Forest model analyzes the network traffic and identifies observations that significantly differ from normal traffic patterns. The detected results are presented through graphical visualizations, including histograms and scatter plots, using Matplotlib and Seaborn. These visualizations help users understand traffic distributions and identify potential anomalous patterns. The system also provides additional functionalities, including result export, report generation through REST APIs, and synthetic network traffic data generation for testing purposes. Based on the detected anomaly characteristics, the framework can provide automated mitigation recommendations to assist users in responding to potential security threats. All detection activities and results are recorded with timestamps to support monitoring, traceability, and analysis. Overall, the proposed framework provides a scalable approach for network anomaly detection and proactive security monitoring in dynamic network environments.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-18
DOI
https://doi.org/10.5281/zenodo.22825440
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

ADVANCED ANOMALY DETECTION IN NETWORK TRAFFIC USING ENSEMBLE MACHINE LEARNING

A Raja mohammed
Zenodo (CERN European Organization for Nuclear Research)
Network Security and Intrusion Detection
article

ADVANCED ANOMALY DETECTION IN NETWORK TRAFFIC USING ENSEMBLE MACHINE LEARNING

A Raja mohammed
article en

Abstract

The proposed system is a web-based network traffic anomaly detection framework designed to identify unusual or potentially malicious network activities in real time. The system uses the Isolation Forest algorithm, an unsupervised machine learning technique that detects anomalous observations in high-dimensional datasets without requiring predefined normal traffic labels.The framework is implemented using Flask as the web application backend. Users can upload network traffic data in CSV format, after which the system performs automated preprocessing and anomaly detection. The preprocessing stage includes handling missing values, standardizing numerical features, and validating relevant data parameters to improve the reliability of the detection process. After preprocessing, the Isolation Forest model analyzes the network traffic and identifies observations that significantly differ from normal traffic patterns. The detected results are presented through graphical visualizations, including histograms and scatter plots, using Matplotlib and Seaborn. These visualizations help users understand traffic distributions and identify potential anomalous patterns. The system also provides additional functionalities, including result export, report generation through REST APIs, and synthetic network traffic data generation for testing purposes. Based on the detected anomaly characteristics, the framework can provide automated mitigation recommendations to assist users in responding to potential security threats. All detection activities and results are recorded with timestamps to support monitoring, traceability, and analysis. Overall, the proposed framework provides a scalable approach for network anomaly detection and proactive security monitoring in dynamic network environments.

Zenodo (CERN European Organization for Nuclear Research)
Hindustan Institute of Technology and Science (IN)
Life below water
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

ADVANCED ANOMALY DETECTION IN NETWORK TRAFFIC USING ENSEMBLE MACHINE LEARNING — A Raja mohammed · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS