Research Article

Integrating Traffics with Network Device Logs for Anomaly Detection

Table 7

The detection results over HTTP botnet.

Http BotnetFPFN

10-fold KNN for traffics5.5%4.8%
10-fold SVM for traffics5.3%5.0%
10-fold KNN for logs6.3%5.9%
10-fold SVM for logs6.3%5.8%
10-fold SVM for logs-and-traffics3.6%2.9%
10-fold KNN for logs-and-traffics3.8%2.7%
TLCD (GBDT)2.5%2.8%