Building a Hybrid Anomaly Detection Engine for Network Flows
š§ Building a Hybrid Anomaly Detection Engine for Network Flows 1ļøā£ Background flowenricher already enriched NetFlow/IPFIX data with ASN, GeoIP, DNS, etc., and had an Isolation Forest (iForest)ābased anomaly detector. We wanted to make the anomaly detection more stable, explainable, and sensitive to different attack patterns without constant retuning ā so we added two complementary … Read more