- Research Article
1
- 10.62660/bcstu/2.2025.63
Intrusion detection in telecommunications networks using network traffic analysis
- Apr 22, 2025
- Bulletin of Cherkasy State Technological University
- Andriy Riy + 1 more +1
The growth of cyber threats and network traffic has highlighted the need for effective methods for detecting anomalies. The purpose of the study was to develop a hybrid model for detecting anomalies in telecommunications networks with increased accuracy based on comparative analysis of uncontrolled algorithms. Four main algorithms were compared: Isolation Forest, Local Outlier Factor (LOF), One-Class Support Vector Machine (SVM), and Elliptic Envelope using simulated network traffic data. Analysis methods included data normalisation using Z-score and Min-Max Scaling to eliminate large-scale differences between traits. An ensemble of 100 decision trees was used to improve the accuracy of anomaly detection. As a result, it was found that Isolation Forest provided the highest accuracy of anomaly detection (F1-Score = 85.8%) and high processing speed (processing time per 10,000 records in 2.5 seconds), which is important for real-world conditions of telecommunications networks with large amounts of data. LOF showed high accuracy in detecting local anomalies, but with greater computational complexity. The one-class SVM algorithm detected global anomalies, but showed lower accuracy for local ones. Elliptic Envelope had limited performance due to the assumption of normal data distribution. Additionally, a comprehensive model was developed that combined the advantages of Isolation Forest, LOF, and Density-Based Spatial Clustering of applications with Noise, which allowed increasing the F1-Score to 88% and exceeding the results of individual models. The hybrid model showed adaptability to multimodal distributions and efficiency in detecting local anomalies. Practical significance lies in improving the accuracy and stability of network security systems and form the basis for adaptive real-time algorithms, which allowed cybersecurity and telecommunications specialists to more effectively monitor and protect networks from threats
Read more