Home / Current Issue / Paper 1711113
Comparison of Selected Machine Learning Techniques in Cyberattack Anomaly Detection
Subject area: Science,Engineering and Technology · Area of research: Computer Science, Cybersecurity, Machine Learning
DOI: https://doi.org/10.64388/IREV9I4-1711113-3371
Abstract
The digital age has ushered in unprecedented connectivity and technological advancement, which have also introduced a surge in sophisticated and frequent cyber threats. To safeguard systems, anomaly detection has become a cornerstone of cybersecurity, enabling the identification of deviations from normal system behaviour. This study presents a comparative analysis of three machine learning techniques?Isolation Forest, Long Short-Term Memory (LSTM), and Q-Learning?for cyberattack anomaly detection. The study designed and implemented a system using the CICIDS-2017 dataset (2,830,743 records) in Python, preceded by data preprocessing and feature engineering. Evaluation metrics, including Accuracy, F1-Score, and error rates (FPR, FNR) revealed a clear performance hierarchy. The LSTM model proved superior, achieving a near-perfect Accuracy of 99.53% with minimal errors (FPR: 0.35%, FNR: 0.50%). Q-Learning showed strong, adaptive potential, recording an Accuracy of 92.80% and an F1-Score of 90.25%, though with higher error rates (FPR: 8.58%). Conversely, the unsupervised Isolation Forest was inadequate for this labeled task, with metrics around 50%. The findings establish LSTM as ideal for maximum accuracy, Q-Learning as a viable option for dynamic environments, and highlight the limitations of simple unsupervised methods on complex security datasets.
Keywords
Cyberattack, Anomaly, Detection, Machine, Learning, Isolation Forest, Q-Learning, LSTM, Long Short-Term, Memory.
References
[1] ADDIN ZOTERO_BIBL {"uncited":[],"omitted":[],"custom":[]} CSL_BIBLIOGRAPHY Al Farizi, W. S., Hidayah, I., & Rizal, M. N. (2021). Isolation Forest Based Anomaly Detection: A Systematic Literature Review. 2021 8th International Conference on Information Technology, Computer and Electrical Engineering (ICITACEE), 118–122. https://doi.org/10.1109/ICITACEE53184.2021.9617498
[2] Al-Shaymaa, Y., Yassine, A., & Hajjdi, A. (2019). Anomaly detection in distributed systems: A survey of the state-of-the-art. IEEE Communications Surveys & Tutorials, 21(3), 2250–2283.
[3] Bai, X., Zhang, Y., Wang, S., & He, H. (2020). Network anomaly detection using a hybrid method of random forest and principal component analysis. IEEE Access, 8, 79415–79427. https://doi.org/10.1109/ACCESS.2020.2990101
[4] Barbariol, T., Chiara, F. D., Marcato, D., & Susto, G. A. (2021). A Review of Tree-Based Approaches for Anomaly Detection. Control Charts and Machine Learning for Anomaly Detection in Manufacturing, 149–185. https://doi.org/10.1007/978-3-030-83819-5_7
[5] Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys (CSUR). Springer, 41, 58. https://doi.org/10.1145/1541880.1541882
[6] Clarke, R., Stavrou, L., & Wright, G. (2018). The Net: A Tailored Cyber Threat Intelligence Framework for Cyber Security. Journal of Information Security, 9(01), 1–17.
[7] Jones, S. B., & Sielken, R. S. (2000). Computer system intrusion detection: A survey. University of Virginia Technical Report, 35, 16–22.
[8] Kim, M., Lee, C., & Kim, J. (2021). Anomaly detection using autoencoders in network traffic. IEEE Transactions on Information Forensics and Security, 16(2), 320–328. https://doi.org/10.1109/TIFS.2020.3025136
[9] Kshetri, N. (2017). Cybersecurity and cyberwarfare: A review of the literature. Journal of Information Technology & Politics, 14(2), 149–164.
[10] Modi, C., Patel, D., & Borisaniya, B. (2017). A survey on anomaly detection in network traffic. Journal of Intelligent Information Systems, 49(2), 267–293.
[11] Santos, I., Brezo, F., & Ugarte-Pedrero, X. (2019). Semi-supervised anomaly detection for cybersecurity. Journal of Information Security and Applications, 44, 146–156. https://doi.org/10.1016/j.jisa.2018.10.005
[12] Sutton, R., & Barto, A. (2022). Reinforcement Learning: An Introduction (2nd ed.). MIT Press.
[13] Wu, Z., Liu, J., & Zhang, J. (2020). Real-time anomaly detection using LSTM in industrial IoT networks. IEEE Internet of Things Journal, 7(8), 7262–7270. https://doi.org/10.1109/JIOT.2020.2972211
[14] Yu, B., Zhang, Y., Xie, W., Zuo, W., Zhao, Y., & Wei, Y. (2023). A Network Traffic Anomaly Detection Method Based on Gaussian Mixture Model. Electronics, 12(6), 1397. https://doi.org/10.3390/electronics12061397
How to cite this paper
@article{1711113,
author = {Dorcas Atinuke Adedokun, Wasiu Oladimeji Ismaila, Simeon Ayoade Adedokun, Elizabeth A. Amusan, Folasade Muibat Ismaila},
title = {Comparison of Selected Machine Learning Techniques in Cyberattack Anomaly Detection},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {4},
pages = {342-353},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1711113.pdf},
abstract = {The digital age has ushered in unprecedented connectivity and technological advancement, which have also introduced a surge in sophisticated and frequent cyber threats. To safeguard systems, anomaly detection has become a cornerstone of cybersecurity, enabling the identification of deviations from normal system behaviour. This study presents a comparative analysis of three machine learning techniques?Isolation Forest, Long Short-Term Memory (LSTM), and Q-Learning?for cyberattack anomaly detection. The study designed and implemented a system using the CICIDS-2017 dataset (2,830,743 records) in Python, preceded by data preprocessing and feature engineering. Evaluation metrics, including Accuracy, F1-Score, and error rates (FPR, FNR) revealed a clear performance hierarchy. The LSTM model proved superior, achieving a near-perfect Accuracy of 99.53% with minimal errors (FPR: 0.35%, FNR: 0.50%). Q-Learning showed strong, adaptive potential, recording an Accuracy of 92.80% and an F1-Score of 90.25%, though with higher error rates (FPR: 8.58%). Conversely, the unsupervised Isolation Forest was inadequate for this labeled task, with metrics around 50%. The findings establish LSTM as ideal for maximum accuracy, Q-Learning as a viable option for dynamic environments, and highlight the limitations of simple unsupervised methods on complex security datasets.},
keywords = {Cyberattack, Anomaly, Detection, Machine, Learning, Isolation Forest, Q-Learning, LSTM, Long Short-Term, Memory.},
month = {October},
doi = {https://doi.org/10.64388/IREV9I4-1711113-3371}
}