Performance Analysis of Different Machine Learning Algorithms in Threat Detection
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [en]
This thesis evaluates and compares five supervised Machine Learning algorithms based on their performance in detecting and classifying network traffic, including both malicious threats and normal. Doing so by binary classification and using an imbalanced dataset. The algorithms used were Random Forest, XGBoost, KNN, Linear SVC and Logistic Regression. A subset of the CICIDS2017 dataset was used and this thesis presents how the preprocessing was done. Hyperparameter tuning was performed to modify the performance of the algorithm. This thesis hopes to contributes to the Machine Learning field when it comes to threat detection. Specifically, using an imbalanced dataset with mutual information for feature selection and hyperparameter tuning. To ensure a comprehensive performance evaluation, multiple metrics were utilized, including macro-F1-score, -Precision, -Recall aswell as PR-AUC, and Execution Time. These metrics were chosen to account for the class imbalance in the dataset. The results show that the ensemble algorithms, Random Forest and XGBoost, outperformed the other algorithms scoring highest on almost every metric. The ensemble algorithms were closely followed by KNN who scored the highest on the Recall metric but had a downside that it had a significant Execution Time compared Random Forest and XGBoost. Linear SVC and Logistic Regression showed a poor performance throughout the tests, when compared to the other algorithms. Linear SVC and Logistic Regression underperformed especially in Recall meaning that they had a problem identifying samples in the imbalanced dataset. The findings in this thesis show that Random Forest, XGBoost and KNN performed the best when it came to threat detection.
Place, publisher, year, edition, pages
2025. , p. 51
Keywords [en]
Machine Learning, threat detection, imbalanced dataset, Supervised-learning, CICIDS2017, Random Forest, XGBoost, KNN, LinearSVC, Logistic Regression
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23699Local ID: EHD500OAI: oai:DiVA.org:hv-23699DiVA, id: diva2:1979453
Subject / course
Computer engineering
Educational program
Nätverksteknik med IT-säkerhet
Supervisors
Examiners
2025-07-222025-06-302025-09-30Bibliographically approved