Skip to main content

Machine Learning for Anomaly Detection in Network Traffic

A Final Year Project by Luke Morris

An overview

I will be attempting to create a solution including machine learning to detect anomalies in a given dataset of network traffic. This will involve picking apart a PCAP provided by the user or using (wire|t)shark / tcpdump to read packets directly from the network to provide the machine learning algorithm with data. The ML algorithm will then be able to 'learn' normal traffic sequences. This enables the algorithm to determine when an anomaly is detected and thus alert the owner of the network.

This project will be in the form of:

  • A final report including a literature review
  • This software
  • A portfolio including meeting minutes, CV and a self review

The software provided in this project contains a database, a machine learning algorithm trained to detect anomalies in a PCAP file, and a system to alert users.

Installing the software

This software is available on PyPI as mlads_lukem_fyp and can be installed using pip:

pip install mlads_lukem_fyp

Running the software

To run the software and begin detecting anomalies, run the MLADS.py file from the mlads_lukem_fyp directory.

Alternatively:

>>> from mlads_lukem_fyp.MLADS import start_mlads
>>> start_mlads()

Using MLADS

View Alerts

The page used to view previous alerts or detections by the software. Alerts can be searched through using the fields at the top of the page.

When an alert is highlighted, further details on the alert can be viewed.

Analyse PCAPs

PCAP files can be 'uploaded' to the software. The file is fed through a feature extractor into a CSV that is then used by the machine learning algorithm.

Alerts are generated and sent via SMS and email. These alerts can also be viewed in the 'View Alerts' page.

This page runs very slowly when loading a large file, please be patient.

Edit Contacts

The contacts to be alerted when the software detects anomalies are kept up to date here, and contacts stored in a database.

Live Capture

Coming soon...

Metadata

Release files for mlads-lukem-fyp 1.0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mlads-lukem-fyp 1.0.5
File Size Uploaded
mlads-lukem-fyp-1.0.5.tar.gz 21.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mlads-lukem-fyp 1.0.5
File Interpreter ABI Platform
mlads_lukem_fyp-1.0.5-py2.py3-none-any.whl Python 3, Python 2 none any Details

Total release size: 63.4 kB

Release files / mlads-lukem-fyp-1.0.5.tar.gz

Download URL mlads-lukem-fyp-1.0.5.tar.gz
Size 21.1 kB
Tags Source
SHA-256 checksum
How to use checksums
51530d8fe96b1a90e576e555be56af9a2d065ccc53c768a4428de8ee69e07939
BLAKE2b-256 checksum
How to use checksums
4845d2d60fa517e0b6b7b78aa28152ae7fd99533f6a46a5f0aada9ba7aa5fb3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.48.0 CPython/3.7.4

Release files / mlads_lukem_fyp-1.0.5-py2.py3-none-any.whl

Download URL mlads_lukem_fyp-1.0.5-py2.py3-none-any.whl
Size 42.3 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
6c88cf39395401b1c610e38823e45af6a533919e69a16fd71ea014fd7f40c69e
BLAKE2b-256 checksum
How to use checksums
28ebf3714fd49da2873c93e89487be06ed4efd1295e6bf85cc423c754339521a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.48.0 CPython/3.7.4

Release history Release notifications | RSS feed

This release

1.0.5 This release

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page