Network Attack Detection System

Models analyze network traffic and detect signs of malicious activity. The system includes detection quality assessment by attack class and review of false positives.

Security · Network Traffic

The task

Develop models that detect malicious activity in network traffic and tune their use for different attack classes and for the workload of the analysts on duty.

Training and evaluation

Models are trained on labeled traffic datasets with class imbalance taken into account. Quality is measured separately by attack type, so an overall metric does not hide weak spots in detection.

Review of false positives and of the connection features behind a model’s decision is supported.

Operational logic

Thresholds are chosen with regard to missed detections, false positives and the volume of events a duty shift can realistically process.

The system combines detection, quality evaluation and model tuning for real-world operating conditions.

Contacts

IK Resurs LLC

info@ik-resurs.ru+7 919 32 080 55