Master'sOpen Access

Classification and anomaly detection of attacks and threats coming from the internal network in corporate networks using machine learning methods

2025
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Oğuzhan Kendirli

Abstract (EN)

Corporate networks are highly vulnerable to both external and internal cyber threats. With the rapid increase in digitalization, organizations are exposed to more network connections and devices, which in turn introduce new security risks. While most corporate security strategies primarily focus on external attacks, potential threats originating from the internal network are often overlooked. However, an internal security breach can cause consequences as severe as external attacks, leading to financial losses and reputational damage. In this study, a machine learning–based threat detection and classification model was developed using real-time threat logs obtained from next-generation firewall systems. In the first phase, only firewall logs were analyzed; in the second phase, behavioral features derived from the CICIDS2018 dataset were integrated to reevaluate the system's performance. GRU, LSTM, XGBoost, and MLP algorithms were employed, and model performance was evaluated based on the F1-score, which balances precision and recall. The results indicate that the XGBoost model achieved the highest performance in both phases, with the F1-score improving from 0.9839 to 0.9909 after the inclusion of behavioral data. This improvement demonstrates that behavioral analysis significantly enhances threat detection performance. LSTM and GRU models produced consistent results, particularly in the dataset enriched with behavioral features, due to their ability to capture temporal dependencies. The findings reveal that machine learning–based approaches provide a strong and practical method for accurately detecting and classifying threats in next-generation firewall logs. Keywords: Anomaly Detection, Behavioral Analysis, Firewall, Threat Classification, XGBoost

Author

Sercan Akçalı

How to Cite

Sercan Akçalı (Master Thesis). Classification and anomaly detection of attacks and threats coming from the internal network in corporate networks using machine learning methods, 2025, Düzce University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Düzce University