Hybrid machine learning for a real-time anomaly detection system in computer networks with the ELK stack using system logs and netflow data (Record no. 56709)

MARC details
000 -LEADER
fixed length control field 03791nam a2200397 a 4500
005 - DATE AND TIME OF LATEST TRANSACTION
control field 20260818134000.0
008 - FIXED-LENGTH DATA ELEMENTS--GENERAL INFORMATION
fixed length control field 260219s20259999th mm 000 0 eng d
035 ## - SYSTEM CONTROL NUMBER
System control number .b12477564
099 #9 - LOCAL FREE-TEXT CALL NUMBER (OCLC)
Classification number AIT Thesis no.DSAI-25-08
100 1# - MAIN ENTRY--PERSONAL NAME
Personal name Sonakul Kamnuanchai
245 10 - TITLE STATEMENT
Title Hybrid machine learning for a real-time anomaly detection system in computer networks with the ELK stack using system logs and netflow data
260 ## - PUBLICATION, DISTRIBUTION, ETC.
Place of publication, distribution, etc. Pathum Thani, Thailand :
Name of publisher, distributor, etc. Asian Institute of Technology,
Date of publication, distribution, etc. 2025
300 ## - PHYSICAL DESCRIPTION
Extent 90 leaves :
Other physical details ill.+
Accompanying material 1 online resource
490 1# - SERIES STATEMENT
Series statement Thesis ;
Volume/sequential designation no. DSAI-25-08
500 ## - GENERAL NOTE
General note A thesis submitted in partial fulfillment of the requirements for the degree of Master of Engineering in Data Science and Artificial Intelligence
502 ## - DISSERTATION NOTE
Dissertation note Thesis (M. Eng.) - Asian Institute of Technology, 2025
520 ## - SUMMARY, ETC.
Summary, etc. The increasing intricacy and prevalence of cyber threats in modern computer networks highlight the need for effective anomaly detection systems to protect sensitive information. Traditional methods face challenges such as limited real-time processing, reliance on simple binary classification, and inadequate evaluation using realistic datasets. To address these issues, this research proposes a hybrid machine learning framework for anomaly detection. In the first stage, an autoencoder is used to learn latent represen tations of normal traffic, while an Isolation Forest algorithm detects anomalies based on anomaly scores. The Receiver Operating Characteristic (ROC) curve and Youden{u2019}s Index are employed to determine thresholds, which are then validated against the test labels of the UNSW-NB15 dataset to obtain baseline performance metrics. In the sec ond stage, supervised models including Decision Tree, XGBoost, and Random Forest are trained on the latent features, reconstruction error of the autoencoder, and anomaly scores from the Isolation Forest. Among these, Random Forest achieved the best per formance, significantly improving upon the unsupervised baseline, with an accuracy of 98.81%, precision of 92.00%, recall of 99.25%, F1-score of 95.49%, and a false posi tive rate of only 1.25%. To enable real-time usage, the framework is deployed with the Elastic Stack (ELK), allowing automated alerting, continuous monitoring, and visual ization of security events. The deployed system is further evaluated using real-world NetFlow and Syslog data collected from the Operational Technology (OT) network of the Provincial Electricity Authority (PEA). Controlled attack scenarios including TCP, UDP, and ICMP flood attacks are generated using the Nping tool to validate real-time anomaly detection. The results confirm that the proposed framework performs effec tively under realistic operational conditions and is suitable for practical deployment in critical infrastructure environments.
650 #0 - SUBJECT ADDED ENTRY--TOPICAL TERM
Topical term or geographic name entry element Computer networks
General subdivision Security measures
650 #0 - SUBJECT ADDED ENTRY--TOPICAL TERM
Topical term or geographic name entry element Anomaly detection (Computer security)
650 #0 - SUBJECT ADDED ENTRY--TOPICAL TERM
Topical term or geographic name entry element Machine learning
650 #0 - SUBJECT ADDED ENTRY--TOPICAL TERM
Topical term or geographic name entry element Data protection
700 0# - ADDED ENTRY--PERSONAL NAME
Personal name Chutiporn Anutariya,
Relator term Chairperson
700 0# - ADDED ENTRY--PERSONAL NAME
Personal name Chantri Polprasert,
Relator term Examination Committee
700 0# - ADDED ENTRY--PERSONAL NAME
Personal name Aekavute Sujarae,
Relator term Examination Committee
710 2# - ADDED ENTRY--CORPORATE NAME
Corporate name or jurisdiction name as entry element PEA-AIT Education Cooperation Project,
Relator term Scholarship Donor
710 2# - ADDED ENTRY--CORPORATE NAME
Corporate name or jurisdiction name as entry element AIT Scholarship,
Relator term Scholarship Donor
810 2# - SERIES ADDED ENTRY--CORPORATE NAME
Corporate name or jurisdiction name as entry element Asian Institute of Technology.
Title of a work Thesis ;
Volume/sequential designation no. DSAI-25-08
856 40 - ELECTRONIC LOCATION AND ACCESS
Materials specified Full-Text
Uniform Resource Identifier <a href="http://203.159.5.9/ait-thesis/detail.php?q=B23672">http://203.159.5.9/ait-thesis/detail.php?q=B23672</a>
907 ## - LOCAL DATA ELEMENT G, LDG (RLIN)
a .b12477564
b mnarc
c a
902 ## - LOCAL DATA ELEMENT B, LDB (RLIN)
a 260310
998 ## - LOCAL CONTROL INFORMATION (RLIN)
Operator's initials, OID (RLIN) 0
Cataloger's initials, CIN (RLIN) 260310
First date, FD (RLIN) m
-- h
-- a
-- 0
945 ## - LOCAL PROCESSING INFORMATION (OCLC)
l mnarc
942 ## - ADDED ENTRY ELEMENTS (KOHA)
Koha item type 67-Electronic Resource
909 ## - LOCAL ITEMS USED
Barcode Barcode : -
CREATED CREATED : 2026-02-19
RECORD Id RECORD # : i13574504
LPATRON LPATRON : 0
LCHKIN LCHKIN : -
RENEWALS # RENEWALS : 0
-- # OVERDUE : 0
-- IUSE3 : 0
-- TOT CHKOUT : 0
-- TOT RENEW : 0
Holdings
Withdrawn status Lost status Damaged status Not for loan Home library Current library Shelving location Date acquired Total checkouts Full call number Date last seen Copy number Price effective from Koha item type
      Available for Loans Asian Institute of Technology Library Asian Institute of Technology Library Archives 18/08/2026   AIT Thesis no.DSAI-25-08 18/08/2026 1 18/08/2026 67-Electronic Resource
คัดลอกแล้ว!