Related Experiment Video
Updated: Jun 27, 2025

Design and Analysis for Fall Detection System Simplification
Published on: April 6, 2020
Comparative Analysis of Anomaly Detection Approaches in Firewall Logs: Integrating Light-Weight Synthesis of Security
Adrian Komadina1, Ivan Kovačević1, Bruno Štengl1
1Faculty of Electrical Engineering and Computing, University of Zagreb, 10000 Zagreb, Croatia.
Abstract:
Detecting anomalies in large networks is a major challenge. Nowadays, many studies rely on machine learning techniques to solve this problem. However, much of this research depends on synthetic or limited datasets and tends to use specialized machine learning methods to achieve good detection results. This study focuses on analyzing firewall logs from a large industrial control network and presents a novel method for generating anomalies that simulate real attacker actions within the network without the need for a dedicated testbed or installed security controls. To demonstrate that the proposed method is feasible and that the constructed logs behave as one would expect real-world logs to behave, different supervised and unsupervised learning models were compared using different feature subsets, feature construction methods, scaling methods, and aggregation levels. The experimental results show that unsupervised learning methods have difficulty in detecting the injected anomalies, suggesting that they can be seamlessly integrated into existing firewall logs. Conversely, the use of supervised learning methods showed significantly better performance compared to unsupervised approaches and a better suitability for use in real systems.
More Related Videos
Related Concept Videos
Flame Photometry: Overview
Difference from Background: Limit of Detection
The LOD indicates the presence or absence...

