| 000 | 03791nam a2200397 a 4500 | ||
|---|---|---|---|
| 005 | 20260818134000.0 | ||
| 008 | 260219s20259999th mm 000 0 eng d | ||
| 035 | _a.b12477564 | ||
| 099 | 9 | _aAIT Thesis no.DSAI-25-08 | |
| 100 | 1 | _aSonakul Kamnuanchai | |
| 245 | 1 | 0 | _aHybrid machine learning for a real-time anomaly detection system in computer networks with the ELK stack using system logs and netflow data |
| 260 |
_aPathum Thani, Thailand : _bAsian Institute of Technology, _c2025 |
||
| 300 |
_a90 leaves : _bill.+ _e1 online resource |
||
| 490 | 1 |
_aThesis ; _vno. DSAI-25-08 |
|
| 500 | _aA thesis submitted in partial fulfillment of the requirements for the degree of Master of Engineering in Data Science and Artificial Intelligence | ||
| 502 | _aThesis (M. Eng.) - Asian Institute of Technology, 2025 | ||
| 520 | _aThe increasing intricacy and prevalence of cyber threats in modern computer networks highlight the need for effective anomaly detection systems to protect sensitive information. Traditional methods face challenges such as limited real-time processing, reliance on simple binary classification, and inadequate evaluation using realistic datasets. To address these issues, this research proposes a hybrid machine learning framework for anomaly detection. In the first stage, an autoencoder is used to learn latent represen tations of normal traffic, while an Isolation Forest algorithm detects anomalies based on anomaly scores. The Receiver Operating Characteristic (ROC) curve and Youden{u2019}s Index are employed to determine thresholds, which are then validated against the test labels of the UNSW-NB15 dataset to obtain baseline performance metrics. In the sec ond stage, supervised models including Decision Tree, XGBoost, and Random Forest are trained on the latent features, reconstruction error of the autoencoder, and anomaly scores from the Isolation Forest. Among these, Random Forest achieved the best per formance, significantly improving upon the unsupervised baseline, with an accuracy of 98.81%, precision of 92.00%, recall of 99.25%, F1-score of 95.49%, and a false posi tive rate of only 1.25%. To enable real-time usage, the framework is deployed with the Elastic Stack (ELK), allowing automated alerting, continuous monitoring, and visual ization of security events. The deployed system is further evaluated using real-world NetFlow and Syslog data collected from the Operational Technology (OT) network of the Provincial Electricity Authority (PEA). Controlled attack scenarios including TCP, UDP, and ICMP flood attacks are generated using the Nping tool to validate real-time anomaly detection. The results confirm that the proposed framework performs effec tively under realistic operational conditions and is suitable for practical deployment in critical infrastructure environments. | ||
| 650 | 0 |
_aComputer networks _xSecurity measures |
|
| 650 | 0 | _aAnomaly detection (Computer security) | |
| 650 | 0 | _aMachine learning | |
| 650 | 0 | _aData protection | |
| 700 | 0 |
_aChutiporn Anutariya, _eChairperson |
|
| 700 | 0 |
_aChantri Polprasert, _eExamination Committee |
|
| 700 | 0 |
_aAekavute Sujarae, _eExamination Committee |
|
| 710 | 2 |
_aPEA-AIT Education Cooperation Project, _eScholarship Donor |
|
| 710 | 2 |
_aAIT Scholarship, _eScholarship Donor |
|
| 810 | 2 |
_aAsian Institute of Technology. _tThesis ; _vno. DSAI-25-08 |
|
| 856 | 4 | 0 |
_3Full-Text _uhttp://203.159.5.9/ait-thesis/detail.php?q=B23672 |
| 907 |
_a.b12477564 _bmnarc _ca |
||
| 902 | _a260310 | ||
| 998 |
_b0 _c260310 _dm _eh _fa _g0 |
||
| 945 | _lmnarc | ||
| 942 | _c67 | ||
| 909 |
_aBarcode : - _bCREATED : 2026-02-19 _cRECORD # : i13574504 _dLPATRON : 0 _eLCHKIN : - _f# RENEWALS : 0 _g# OVERDUE : 0 _hIUSE3 : 0 _iTOT CHKOUT : 0 _jTOT RENEW : 0 |
||
| 999 |
_c56709 _d56709 |
||