Team task: improve a single Python ML pipeline on a network intrusion dataset to boost detection of anomaly (positive class) vs normal traffic.
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
python run.pyThe dataset to be audited was provided which consists of a wide variety of intrusions simulated in a military network environment.
It created an environment to acquire raw TCP/IP dump data for a network by simulating a typical US Air Force LAN. The LAN was focused like a real environment and blasted with multiple attacks.
A connection is a sequence of TCP packets starting and ending at some time duration between which data flows to and from a source IP address to a target IP address under some well-defined protocol.
Also, each connection is labelled as either normal or as an attack with exactly one specific attack type. Each connection record consists of about 100 bytes.
For each TCP/IP connection, 41 quantitative and qualitative features are obtained from normal and attack data (3 qualitative and 38 quantitative features) .The class variable has two categories:
- Normal
- Anomalous