Deep and Machine Learning Techniques for Detecting Unbalance Network Traffic
摘要
Network intrusion detection systems (NIDS) safeguard digital infrastructures from cyberthreats. However, the challenge of detecting intrusions within unbalanced network traffic, where legitimate traffic significantly outweighs malicious traffic, remains a critical barrier to improving the performance of NIDS. This comprehensive review explores machine and deep learning techniques designed to address the complexities of unbalanced network traffic in intrusion detection. The review highlights how these techniques improve detection accuracy while minimizing false positives and negatives by analysing recent advancements in machine learning, deep learning, cost-sensitive learning, data augmentation, and hybrid models. We examine various algorithms, including ensemble methods, anomaly detection frameworks, and optimization strategies that dynamically adapt to traffic characteristics. The review identifies existing research gaps, particularly in traditional oversampling and undersampling methods that often introduce bias, and underscores the need for more robust approaches capable of generalizing to real-world network conditions. Our findings suggest that integrating multiple machine learning and deep learning algorithms can provide a scalable and effective solution for modern NIDS, enabling enhanced detection capabilities in highly imbalanced network environments. This review aims to guide future research towards developing more robust and adaptive frameworks for detecting anomalies in network traffic, ultimately strengthening the security posture of digital networks.