Repository logoKCAU
Knowledge Repository
Communities & Collections
All of DSpace
Analytics
  • English
  • العربية
  • বাংলা
  • Català
  • Čeština
  • Deutsch
  • Ελληνικά
  • Español
  • Suomi
  • Français
  • Gàidhlig
  • हिंदी
  • Magyar
  • Italiano
  • Қазақ
  • Latviešu
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Srpski (lat)
  • Српски
  • Svenska
  • Türkçe
  • Yкраї́нська
  • Tiếng Việt
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. Browse by Author

Browsing by Author "Arusei, Mike K."

Filter results by typing the first few letters
Now showing 1 - 2 of 2
  • Results Per Page
  • Sort Options
  • Thumbnail Image
    Item
    An isolation forest model for anomaly detection of Data exfiltration in network traffic Case study – academic institutions network environments
    (KCA University, 2025) Arusei, Mike K.
    Academic institutions are increasingly relying on interconnected networked and to manage critical data and services making them vulnerable to cybersecurity threats such as data exfiltration. Traditional security infrastructures often fail to detect these emerging threats, especially within resource constrained academic environments lacking sufficient expertise. To address this, an anomaly detection model was designed using unsupervised Isolation Forest algorithm, which analyzes key network features identify abnormal outbound traffic indicative of data breaches. The model was evaluated on the CICIDS2017 dataset, focusing on real-world infiltration scenarios, with a case study of academic institutions to ensure contextual relevance. Using recall, precision, and F1-score metrics, the model demonstrated effective detection capabilities. Its significance lies in providing a scalable and practical network security solution for academic institutions, supporting compliance with data protection regulations. However, limitations include reliance on the representativeness of the dataset and adaptability to emerging attack patterns. Future work should include exploration of continuous model refinement and integration with broader security frameworks.
  • Thumbnail Image
    Item
    Detecting Data Exfiltration Anomalies in Academic Networks Using the Isolation Forest Algorithm
    (KCA University, 2025) Arusei, Mike K.; Dr. Njenga, Stephen
    Academic networks face increased risks of data exfiltration due to sensitive personal information and research data. Traditional supervised detection models rely on labeled datasets which are often unavailable in resource constrained institutions. This study investigates the applicability of the unsupervised Isolation Forest algorithm for detecting anomalous network traffic indicative of data exfiltration. The research utilized the CICIDS2017 dataset focusing on the Thursday-WorkingHours-Afternoon-Infiltration subset. Key features including Flow Duration, Total Fwd Packets, Flow Bytes/s, Flow IAT Mean, and Destination Port were preprocessed and normalized for modeling. The model achieved a precision of 1.00, recall of 0.99 and F1-score of 1.00 for anomalous traffic detection successfully identifying approximately 4.8% of flows as anomalous. Comparative analysis with previous methods, including supervised Random Forest and SVM demonstrated that Isolation Forest offers competitive accuracy with lower computational overhead and does not require labeled data. The findings highlight the algorithm’s suitability for academic network monitoring, providing an effective early warning mechanism while emphasizing the importance of threshold tuning to reduce false positives.
KCAU Logo

The KCAU Knowledge Repository provides open access to the research, publications and institutional documents of KCA University.

Quick Links
  • Home
  • Communities
  • Search
  • Statistics
Policies
  • Privacy Policy
  • End User Agreement
  • Send Feedback
Contact Us
  • KCA University, Nairobi, Kenya
  • www.kcau.ac.ke
  • library@kcau.ac.ke

© 2026 KCA University. Powered by DSpace

COAR Notify