Answer the question
In order to leave comments, you need to log in
What traffic parameters should be chosen for its classification into normal and abnormal by the support vector machine (SVM) method?
It is necessary to attribute traffic that comes from a given source to one of two classes, while we receive traffic data only from the header (packet number, time, protocol, source and destination, source and destination ports, and packet length).
Is it possible to use the number of packets arriving per unit of time as a parameter?
Answer the question
In order to leave comments, you need to log in
For anomaly detection, I can advise you to use the aggregate number of packets as a parameter, i.e. for each observation, calculate the sum / average number of packets for the period n. You can try to use aggregation for periods of different duration as different features.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question