ADVANCED ANOMALY DETECTION IN NETWORK TRAFFIC USING ENSEMBLE MACHINE LEARNING
The proposed system is a web-based network traffic anomaly detection framework designed to identify unusual or potentially malicious network activities in real time. The system uses the Isolation Forest algorithm, an unsupervised machine learning technique that detects anomalous observations in high-dimensional datasets without requiring predefined normal traffic labels.The framework is implemented using Flask as the web application backend. Users can upload network traffic data in CSV format, after which the system performs automated preprocessing and anomaly detection. The preprocessing stage includes handling missing values, standardizing numerical features, and validating relevant data parameters to improve the reliability of the detection process. After preprocessing, the Isolation Forest model analyzes the network traffic and identifies observations that significantly differ from normal traffic patterns. The detected results are presented through graphical visualizations, including histograms and scatter plots, using Matplotlib and Seaborn. These visualizations help users understand traffic distributions and identify potential anomalous patterns. The system also provides additional functionalities, including result export, report generation through REST APIs, and synthetic network traffic data generation for testing purposes. Based on the detected anomaly characteristics, the framework can provide automated mitigation recommendations to assist users in responding to potential security threats. All detection activities and results are recorded with timestamps to support monitoring, traceability, and analysis. Overall, the proposed framework provides a scalable approach for network anomaly detection and proactive security monitoring in dynamic network environments.
Authors
- A Raja mohammed (ORCID: https://orcid.org/0009-0001-0395-7719)
Institutions
- Hindustan Institute of Technology and Science (IN)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-18
- DOI
- https://doi.org/10.5281/zenodo.22825440
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00