Research Article | | Peer-Reviewed

Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources

Received: 13 August 2025     Accepted: 22 August 2025     Published: 11 September 2025
Views:       Downloads:
Abstract

This study addresses the challenge of detecting and classifying advanced cyber threats, including distributed denial-of-service (DDoS) and Stealth Attacks, in complex network environments. We propose a hybrid approach that combines machine learning models with a rule-based classifier to improve anomaly detection accuracy. The method uses Random Forest, Gradient Boosting, and Linear Regression to predict normal traffic volume with high precision (R² = 0.99, MSE = 0.000085). Key features include request rate, traffic volume, source IP entropy, flow duration, and protocol diversity. A deviation threshold of 0.5 standard deviations from predicted values effectively identifies anomalies under dynamic conditions. For classification, we introduce a rule-based system that utilizes thresholds, such as a request rate exceeding 100 requests per second for DDoS attacks or a source IP entropy of approximately 0.6907 for Stealth Attacks. This classifier identifies six types of anomalies: DDoS, Slow, Volumetric, Service Outage, Application Layer, and Stealth Attacks. The experimental results demonstrate the effectiveness of our hybrid approach. Compared to existing methods, it achieves higher F1-scores (0.97-1.00) across most attack types. Additionally, it correctly classifies 91% of real traffic (1,246,311 packets) as usual in a synthetic dataset containing 9,660 flows. The proposed method demonstrates strong performance in terms of precision, recall, and computational efficiency, making it suitable for real-time network monitoring.

Published in Advances in Applied Sciences (Volume 10, Issue 3)
DOI 10.11648/j.aas.20251003.15
Page(s) 88-96
Creative Commons

This is an Open Access article, distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution and reproduction in any medium or format, provided the original work is properly cited.

Copyright

Copyright © The Author(s), 2025. Published by Science Publishing Group

Keywords

Anomaly Detection, Cybersecurity, Machine Learning, Rule-based Classification

References
[1] Top Cybersecurity Statistics for 2025, Cobalt. io. [Online]. Available:
[2] January 2025: Recent Cyber Attacks, Data Breaches, Ransomware Attacks, CM-Alliance. [Online]. Available:
[3] Cloudflare, “Record-breaking 5.6 Tbps DDoS attack and global DDoS trends for 2024 Q4,” Jan. 2025. [Online]. Available:
[4] Perepelitsyn, S., Perepelitsyn, A. (2025). Compromise Between Topology Connection, Load Balance and Wireless Sensor Networks’Anomalies (WSN). American Journal of Information Science and Technology, 9(2), 79-86.
[5] Center for Strategic and International Studies, “Significant Cyber Incidents,” 2025. [Online]. Available:
[6] Wang, X., Dai, H., Huang, Z., and Han, Y. “Network traffic anomaly detection based on DGBi-SA model,” Eng. Lett., vol. 33, no. 3, pp. 612-619, 2025. Available:
[7] Palmieri F., “Network anomaly detection based on logistic regression of nonlinear chaotic invariants,” J. Netw. Comput. Appl., vol. 148, p. 102460, 2019. Available:
[8] Fan, C., Kaliamurthy, N. Chen, S., Jiang, H., Zhou, Y., and Campbell, C. “Detection of DDoS Attacks in Software Defined Networking Using Entropy,” Appl. Sci., vol. 12, no. 1, p. 370, 2022. Available:
[9] Alazab, M. “A discrete time-varying greywolf IoT botnet detection system,” Comput. Commun., vol. 192, pp. 405-416, 2022. Available:
[10] Abbasi, M., Shahraki, A., and Taherkordi, A. “Deep learning for network traffic monitoring and analysis (NTMA): A survey,” Comput. Commun., vol. 170, pp. 19-41, 2021. Available:
[11] Van Efferen, L., and Ali-Eldin, A. M. T., “A multi-layer perceptron approach for flow-based anomaly detection,” in Proc. Int. Symp. Netw. Comput. Commun. (ISNCC), IEEE, 2017, pp. 1-6. Available:
[12] Htet P. P., and Thanda, S., “Network traffic anomaly detection based on Apache Spark,” in Proc. Int. Conf. Adv. Inf. Technol. (ICAIT), IEEE, 2019, pp. 222-226. Available:
[13] Zhou, D., Yan, Z., Fu, Y., and Yao, Z. “A survey on network data collection,” J. Netw. Comput. Appl., vol. 116, pp. 9-23, 2018. Available:
[14] Rahmatov, F., and Kholmuminov, O. “Analysis of DDoS Attacks on network electronic resources,” Sci. J. Digit. Transform. Artif. Intell., vol. 2, no. 2, pp. 133-137, 2024. Available:
[15] Nmap: the Network Mapper - Free Security Scanner. Available:
[16] Nunez-Agurto, D., Fuertes, W., Marrone, L., and Macas, M. “Machine Learning-based traffic classification in software-defined networking: A systematic literature review, challenges, and future research directions,” IAENG Int. J. Comput. Sci., vol. 49, no. 4, pp. 1002-1015, 2022. Available:
[17] LOIC (Low Orbit Ion Cannon). Available:
[18] Gradient Boosting in ML. Available:
[19] Linear Regression in Machine Learning. Available:
[20] Poisson Distributions | Definition, Formula & Examples. Available:
[21] Normal Distribution: What It Is, Uses, and Formula. Available:
[22] Cross Validation in Machine Learning. Available:
[23] Wireshark. Available:
[24] Aouedi, O. “Machine Learning-enabled network traffic analysis,” Ph. D. dissertation, Nantes Univ., 2022.
[25] iPerf - The TCP, UDP, and SCTP network bandwidth measurement tool. [Online]. Available:
[26] Rakhmatov, F. “Analysis of threats to web applications and existing methods of protection,” Int. Sci. J. Manage. Market. Finance, vol. 1, no. 2, pp. 96-99, 2024. Available:
[27] Sheng, S. and Wang, X. “Network traffic anomaly detection method based on chaotic neural network,” Alex. Eng. J., vol. 77, pp. 567-579, 2023. Available:
[28] Python (programming language). Available:
[29] Dong, S., and Sarem, M. “DDoS attack detection method based on improved KNN with the degree of DDoS attack in software-defined networks,” IEEE Access, vol. 8, pp. 5039-5048, 2019. Available:
[30] Lee, S., Levanti, K. and Kim, H. S. “Network monitoring: Present and future,” Comput. Netw., vol. 65, pp. 84-98, 2014. Available:
[31] Hänsch, R. Handbook of Random Forests: Theory and Applications for Remote Sensing. Singapore: World Scientific, 2025. Available:
[32] ENISA, “ENISA Threat Landscape 2025,” European Union Agency for Cybersecurity, Jan. 2025. [Online]. Available:
Cite This Article
  • APA Style

    Mukhammadjon, M., Furkat, R., Oybek, K., Norbek, K., Fakhriddin, A. (2025). Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources. Advances in Applied Sciences, 10(3), 88-96. https://doi.org/10.11648/j.aas.20251003.15

    Copy | Download

    ACS Style

    Mukhammadjon, M.; Furkat, R.; Oybek, K.; Norbek, K.; Fakhriddin, A. Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources. Adv. Appl. Sci. 2025, 10(3), 88-96. doi: 10.11648/j.aas.20251003.15

    Copy | Download

    AMA Style

    Mukhammadjon M, Furkat R, Oybek K, Norbek K, Fakhriddin A. Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources. Adv Appl Sci. 2025;10(3):88-96. doi: 10.11648/j.aas.20251003.15

    Copy | Download

  • @article{10.11648/j.aas.20251003.15,
      author = {Musaev Mukhammadjon and Rakhmatov Furkat and Kholmuminov Oybek and Karimov Norbek and Abdirazakov Fakhriddin},
      title = {Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources
    },
      journal = {Advances in Applied Sciences},
      volume = {10},
      number = {3},
      pages = {88-96},
      doi = {10.11648/j.aas.20251003.15},
      url = {https://doi.org/10.11648/j.aas.20251003.15},
      eprint = {https://article.sciencepublishinggroup.com/pdf/10.11648.j.aas.20251003.15},
      abstract = {This study addresses the challenge of detecting and classifying advanced cyber threats, including distributed denial-of-service (DDoS) and Stealth Attacks, in complex network environments. We propose a hybrid approach that combines machine learning models with a rule-based classifier to improve anomaly detection accuracy. The method uses Random Forest, Gradient Boosting, and Linear Regression to predict normal traffic volume with high precision (R² = 0.99, MSE = 0.000085). Key features include request rate, traffic volume, source IP entropy, flow duration, and protocol diversity. A deviation threshold of 0.5 standard deviations from predicted values effectively identifies anomalies under dynamic conditions. For classification, we introduce a rule-based system that utilizes thresholds, such as a request rate exceeding 100 requests per second for DDoS attacks or a source IP entropy of approximately 0.6907 for Stealth Attacks. This classifier identifies six types of anomalies: DDoS, Slow, Volumetric, Service Outage, Application Layer, and Stealth Attacks. The experimental results demonstrate the effectiveness of our hybrid approach. Compared to existing methods, it achieves higher F1-scores (0.97-1.00) across most attack types. Additionally, it correctly classifies 91% of real traffic (1,246,311 packets) as usual in a synthetic dataset containing 9,660 flows. The proposed method demonstrates strong performance in terms of precision, recall, and computational efficiency, making it suitable for real-time network monitoring.
    },
     year = {2025}
    }
    

    Copy | Download

  • TY  - JOUR
    T1  - Algorithm for Detection and Classification of Anomalies in the Traffic of Electronic Network Resources
    
    AU  - Musaev Mukhammadjon
    AU  - Rakhmatov Furkat
    AU  - Kholmuminov Oybek
    AU  - Karimov Norbek
    AU  - Abdirazakov Fakhriddin
    Y1  - 2025/09/11
    PY  - 2025
    N1  - https://doi.org/10.11648/j.aas.20251003.15
    DO  - 10.11648/j.aas.20251003.15
    T2  - Advances in Applied Sciences
    JF  - Advances in Applied Sciences
    JO  - Advances in Applied Sciences
    SP  - 88
    EP  - 96
    PB  - Science Publishing Group
    SN  - 2575-1514
    UR  - https://doi.org/10.11648/j.aas.20251003.15
    AB  - This study addresses the challenge of detecting and classifying advanced cyber threats, including distributed denial-of-service (DDoS) and Stealth Attacks, in complex network environments. We propose a hybrid approach that combines machine learning models with a rule-based classifier to improve anomaly detection accuracy. The method uses Random Forest, Gradient Boosting, and Linear Regression to predict normal traffic volume with high precision (R² = 0.99, MSE = 0.000085). Key features include request rate, traffic volume, source IP entropy, flow duration, and protocol diversity. A deviation threshold of 0.5 standard deviations from predicted values effectively identifies anomalies under dynamic conditions. For classification, we introduce a rule-based system that utilizes thresholds, such as a request rate exceeding 100 requests per second for DDoS attacks or a source IP entropy of approximately 0.6907 for Stealth Attacks. This classifier identifies six types of anomalies: DDoS, Slow, Volumetric, Service Outage, Application Layer, and Stealth Attacks. The experimental results demonstrate the effectiveness of our hybrid approach. Compared to existing methods, it achieves higher F1-scores (0.97-1.00) across most attack types. Additionally, it correctly classifies 91% of real traffic (1,246,311 packets) as usual in a synthetic dataset containing 9,660 flows. The proposed method demonstrates strong performance in terms of precision, recall, and computational efficiency, making it suitable for real-time network monitoring.
    
    VL  - 10
    IS  - 3
    ER  - 

    Copy | Download

Author Information
  • Sections