Network Attack Detection System
Models analyze network traffic and detect signs of malicious activity. The system includes detection quality assessment by attack class and review of false positives.
The task
Develop models that detect malicious activity in network traffic and tune their use for different attack classes and for the workload of the analysts on duty.
Training and evaluation
Models are trained on labeled traffic datasets with class imbalance taken into account. Quality is measured separately by attack type, so an overall metric does not hide weak spots in detection.
Review of false positives and of the connection features behind a model’s decision is supported.
Operational logic
Thresholds are chosen with regard to missed detections, false positives and the volume of events a duty shift can realistically process.
The system combines detection, quality evaluation and model tuning for real-world operating conditions.