Logo Lanfrica
  • Accueil
  • Atlas
  • Analyses
  • Documentation
  • Sign in

© 2026 Lanfrica. Tous droits réservés. Tous les droits d'auteur des ressources affichées sur le site Web Lanfrica appartiennent aux détenteurs de droits d'auteur d'origine, sauf indication contraire explicite.

surafelasfawosen/Ethio-Telecom-Anomaly-Detection-in-Network-Traffic

Domaine:

digital infrastructure

Type de record:

project
Créateur:
sur
Hôte:
An advanced, two-stage Hybrid Machine Learning architecture (Random Forest + Isolation Forest) designed to protect Ethiopian critical infrastructure (Ethio Telecom/Telebirr) from Zero-Day cyber attacks. # Ethio Telecom Advanced Threat Detection System **A Hybrid Machine Learning Architecture for Critical Infrastructure Protection** ## Project Overview This project was developed as a research initiative to protect Ethiopian national infrastructure—specifically **Ethio Telecom** and the **Telebirr** mobile money platform—from sophisticated network intrusions. Traditional firewalls rely on static signatures, which fail against invisible "Zero-Day" attacks. To solve this, I engineered a **Two-Stage Hybrid Anomaly Detection Pipeline** using the NSL-KDD dataset. The resulting model operates not just as a classifier, but as a live Security Operations Center (SOC) dashboard that traces attacker fingerprints (Bytes sent, Failed Logins, Root access attempts) in real-time. --- ## The Hybrid Architecture (Two-Stage Pipeline) Instead of relying on a single algorithm, this project utilizes a sequential gating mechanism: * **STAGE 1: The Supervised Firewall (Random Forest):** All incoming traffic is instantly scanned by a 100-tree Random Forest Multi-Class model. Evaluated using Gini Impurity, it identifies and instantly destroys 99% of historical, known threats (DoS, Probing, U2R, R2L). * **STAGE 2: The Zero-Day Trap (Isolation Forest):** If a hacker disguises an attack to bypass Stage 1, the packet is passed to a Semi-Supervised Isolation Forest. Trained *exclusively* on pure, normal traffic, this algorithm calculates mathematical path lengths to isolate hidden, never-before-seen anomalies. --- ## Key Results & Innovations * **Precision Targeting:** Successfully mapped 39 distinct raw attack strings into 4 standard categories (DoS, Probe, U2R, R2L) for streamlined classification. * **Class Imbalance Resolution:** Handled severe dataset imbalance by injecting **SMOTE** (Synthetic Minority Over-sampling Technique) to teach the model how to catch extremely rare (but highly destructive) root-level server breaches. * **Minimized False Alarms:** By switching the Isolation …

Visit

github.com

Languages

Amharic