Arusei, Mike K.2026-06-282025https://repository.kcau.ac.ke/handle/123456789/1170Academic institutions are increasingly relying on interconnected networked and to manage critical data and services making them vulnerable to cybersecurity threats such as data exfiltration. Traditional security infrastructures often fail to detect these emerging threats, especially within resource constrained academic environments lacking sufficient expertise. To address this, an anomaly detection model was designed using unsupervised Isolation Forest algorithm, which analyzes key network features identify abnormal outbound traffic indicative of data breaches. The model was evaluated on the CICIDS2017 dataset, focusing on real-world infiltration scenarios, with a case study of academic institutions to ensure contextual relevance. Using recall, precision, and F1-score metrics, the model demonstrated effective detection capabilities. Its significance lies in providing a scalable and practical network security solution for academic institutions, supporting compliance with data protection regulations. However, limitations include reliance on the representativeness of the dataset and adaptability to emerging attack patterns. Future work should include exploration of continuous model refinement and integration with broader security frameworks.enAn isolation forest model for anomaly detection of Data exfiltration in network traffic Case study – academic institutions network environmentsThesis