Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Performance Analysis of Different Machine Learning Algorithms in Threat Detection
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This thesis evaluates and compares five supervised Machine Learning algorithms based on their performance in detecting and classifying network traffic, including both malicious threats and normal. Doing so by binary classification and using an imbalanced dataset. The algorithms used were Random Forest, XGBoost, KNN, Linear SVC and Logistic Regression. A subset of the CICIDS2017 dataset was used and this thesis presents how the preprocessing was done. Hyperparameter tuning was performed to modify the performance of the algorithm. This thesis hopes to contributes to the Machine Learning field when it comes to threat detection. Specifically, using an imbalanced dataset with mutual information for feature selection and hyperparameter tuning. To ensure a comprehensive performance evaluation, multiple metrics were utilized, including macro-F1-score, -Precision, -Recall aswell as PR-AUC, and Execution Time. These metrics were chosen to account for the class imbalance in the dataset. The results show that the ensemble algorithms, Random Forest and XGBoost, outperformed the other algorithms scoring highest on almost every metric. The ensemble algorithms were closely followed by KNN who scored the highest on the Recall metric but had a downside that it had a significant Execution Time compared Random Forest and XGBoost. Linear SVC and Logistic Regression showed a poor performance throughout the tests, when compared to the other algorithms. Linear SVC and Logistic Regression underperformed especially in Recall meaning that they had a problem identifying samples in the imbalanced dataset. The findings in this thesis show that Random Forest, XGBoost and KNN performed the best when it came to threat detection.

Place, publisher, year, edition, pages
2025. , p. 51
Keywords [en]
Machine Learning, threat detection, imbalanced dataset, Supervised-learning, CICIDS2017, Random Forest, XGBoost, KNN, LinearSVC, Logistic Regression
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23699Local ID: EHD500OAI: oai:DiVA.org:hv-23699DiVA, id: diva2:1979453
Subject / course
Computer engineering
Educational program
Nätverksteknik med IT-säkerhet
Supervisors
Examiners
Available from: 2025-07-22 Created: 2025-06-30 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(1485 kB)68 downloads
File information
File name FULLTEXT01.pdfFile size 1485 kBChecksum SHA-512
9983c5081c328248ac6314e2fedc968e6f1547bc374a18eca6b8bcd08f97615434b9a4578b555c54491112581f199ceac26f1e4cc43b2233c0f12e8e676b8230
Type fulltextMimetype application/pdf

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 68 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 121 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf