Classification and anomaly detection of attacks and threats coming from the internal network in corporate networks using machine learning methods
2025
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Oğuzhan Kendirli
Abstract (EN)
Corporate networks are highly vulnerable to both external and internal cyber threats. With the rapid increase in digitalization, organizations are exposed to more network connections and devices, which in turn introduce new security risks. While most corporate security strategies primarily focus on external attacks, potential threats originating from the internal network are often overlooked. However, an internal security breach can cause consequences as severe as external attacks, leading to financial losses and reputational damage. In this study, a machine learning–based threat detection and classification model was developed using real-time threat logs obtained from next-generation firewall systems. In the first phase, only firewall logs were analyzed; in the second phase, behavioral features derived from the CICIDS2018 dataset were integrated to reevaluate the system's performance. GRU, LSTM, XGBoost, and MLP algorithms were employed, and model performance was evaluated based on the F1-score, which balances precision and recall. The results indicate that the XGBoost model achieved the highest performance in both phases, with the F1-score improving from 0.9839 to 0.9909 after the inclusion of behavioral data. This improvement demonstrates that behavioral analysis significantly enhances threat detection performance. LSTM and GRU models produced consistent results, particularly in the dataset enriched with behavioral features, due to their ability to capture temporal dependencies. The findings reveal that machine learning–based approaches provide a strong and practical method for accurately detecting and classifying threats in next-generation firewall logs. Keywords: Anomaly Detection, Behavioral Analysis, Firewall, Threat Classification, XGBoost
Author
Sercan Akçalı
How to Cite
Sercan Akçalı (Master Thesis). Classification and anomaly detection of attacks and threats coming from the internal network in corporate networks using machine learning methods, 2025, Düzce University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Düzce University
- A review of Cem Akaş's novels(2021)
- New midpoint type inequalities for generalized fractional integrals(2021)
- Material culture in Mostarli Hasan Ziya'i Divan(2021)
- The life of Ebu'l-Hasen Ali b. Ahmed b. Muhammed en-Nîsâbûrî el-Vâhidî and his method in the tafsir named el-Vecîz fî Tefsîr-i Kitabi'l-Azîz(2021)
- Intertextuality in Alev Alatlı's novel's(2022)
- Visual interpretations on dark humor(2022)
