DOE OSTI · code-168082
Anomaly Detection On Network Traffic Using A Sequence Model Approach
Abstract
The code ingests Zeek logs derived from network packet captures, applies a DBSCAN model, Gower distance to build a feature set as input into a transformer model that will output anomaly scores and provides the option to set a threshold as to what’s considered an anomaly.
Keep this discovery
Explore connections, maps & timelines
Quach, Anna [Idaho National Laboratory (INL), Idaho Falls, ID (United States)], Rogers, Dempsey [Idaho National Laboratory (INL), Idaho Falls, ID (United States)], Katopodis, Alexander [Idaho National Laboratory (INL), Idaho Falls, ID (United States)], Devaney, Garrett [Idaho National Laboratory (INL), Idaho Falls, ID (United States)]. 2025-09-24. Anomaly Detection On Network Traffic Using A Sequence Model Approach. https://doi.org/10.11578/dc.20251024.4
Cite the original work for its findings. Save a collection to share your selection of sources.