{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T11:18:03Z","timestamp":1785755883596,"version":"3.56.0"},"reference-count":30,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T00:00:00Z","timestamp":1762128000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:p>Information and communication technology (ICT) is crucial for maintaining efficient communications, enhancing processes, and enabling digital transformation. As ICT becomes increasingly significant in our everyday lives, ensuring its security is crucial for maintaining digital trust and resilience against evolving cyber threats. These technologies generate a large amount of data that should be analyzed simultaneously to detect threats to an ICT system and protect the sensitive information it may contain. NetFlow is a network protocol that can be used to monitor network traffic, collect Internet Protocol (IP) addresses, and detect anomalies in NetFlow. The article follows the design science research (DSR) methodology to reach an objective of providing a methods for developing a set of features for NetFlow analysis with a machine learning. The sets of features were analyzed and validated by implementing anomaly detection with the K-means clustering algorithm and time-series forecasting using the long short-term memory (LSTM) method. The study provides two separate sets of features for both machine learning methods (24 features for clustering and 14 for LSTM), an overview of the anomaly detection methods used in this research and a method to combine both machine learning approaches. Furthermore, this study introduces a method that integrates the outputs of both models and evaluates the reliability of the final decision based on Bayes' theorem and previous performance of the models.<\/jats:p>","DOI":"10.3389\/fcomp.2025.1676362","type":"journal-article","created":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T07:05:51Z","timestamp":1762153551000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Anomaly detection in netflow traffic: workflow for dataset preparation and analysis"],"prefix":"10.3389","volume":"7","author":[{"given":"Evita","family":"Roponena","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Inese","family":"Po\u013caka","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ja\u00af nis","family":"Grabis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2025,11,3]]},"reference":[{"key":"B1","doi-asserted-by":"publisher","first-page":"24","DOI":"10.13189\/wjcat.2017.050202","article-title":"Outlier detection and removal algorithm in k-means and hierarchical clustering","volume":"5","author":"Barai","year":"2017","journal-title":"World J. Comput. Appl. Technol"},{"key":"B2","unstructured":"2025. gada 1. Ceturksnis Latvijas Kibertelp\u0101\n          \n          2025"},{"key":"B3","doi-asserted-by":"publisher","first-page":"1757","DOI":"10.1007\/s00500-013-1218-0","article-title":"Network security management with traffic pattern clustering","volume":"18","author":"Chiou","year":"2014","journal-title":"Soft Comput"},{"key":"B4","unstructured":"Chollet\n              F.\n            \n          \n          Keras\n          \n          2015"},{"key":"B5","volume-title":"Netflow Version 9 Flow-Record Format","year":"2011"},{"key":"B6","doi-asserted-by":"crossref","DOI":"10.1109\/NCA51143.2020.9306732","article-title":"\u201cGo with the flow: clustering dynamically-defined netflow features for network intrusion detection with dynids,\u201d","volume-title":"2020 IEEE 19th International Symposium on Network Computing and Applications, NCA 2020","author":"Dias","year":"2020"},{"key":"B7","volume-title":"Towards a Rigorous Science of Interpretable Machine Learning","author":"Doshi-Velez","year":"2017"},{"key":"B8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1111\/insr.12243","article-title":"Bayesian model averaging: a systematic review and conceptual classification","volume":"86","author":"Fragoso","year":"2018","journal-title":"Int. Stat. Rev"},{"key":"B9","doi-asserted-by":"publisher","first-page":"100819","DOI":"10.1016\/j.iot.2023.100819","article-title":"Intrusion detection system for large-scale iot netflow networks using machine learning with modified arithmetic optimization algorithm","volume":"22","author":"Fraihat","year":"2023","journal-title":"Internet Things"},{"key":"B10","first-page":"139","article-title":"\u201cBotminer: clustering analysis of network traffic for protocol- and structure-independent botnet detection,\u201d","volume-title":"Proceedings of the 17th USENIX Security Symposium","author":"Gu","year":"2008"},{"key":"B11","first-page":"39","volume-title":"2 - Getting to Know Your Data","author":"Han","year":"2012"},{"key":"B12","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1177\/2515245919898657","article-title":"A conceptual introduction to bayesian model averaging","volume":"3","author":"Hinne","year":"2020","journal-title":"Adv. Methods Pract Psychol. Sci"},{"key":"B13","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1016\/j.patrec.2009.09.011","article-title":"Data clustering: 50 years beyond k-means","volume":"31","author":"Jain","year":"2010","journal-title":"Pattern Recognit. Lett"},{"key":"B14","doi-asserted-by":"publisher","first-page":"111","DOI":"10.5391\/IJFIS.2016.16.2.111","article-title":"Frequentist and bayesian learning approaches to artificial intelligence","volume":"16","author":"Jun","year":"2016","journal-title":"Int. J. Fuzzy Logic Intell. Syst"},{"key":"B15","doi-asserted-by":"crossref","DOI":"10.1145\/3600160.3605094","article-title":"\u201cModern netflow network dataset with labeled attacks and detection methods,\u201d","volume-title":"ACM International Conference Proceeding Series","author":"Komisarek","year":"2023"},{"key":"B16","first-page":"340","article-title":"\u201cArtificial intelligence and big data driven is security management solution with applications in higher education organizations,\u201d","volume-title":"Proceedings of the 2021 17th International Conference on Network and Service Management: Smart Management for Future Networks and Services, CNSM 2021","author":"Minkevics","year":"2021"},{"key":"B17","doi-asserted-by":"publisher","first-page":"757","DOI":"10.1016\/j.jksuci.2023.01.014","article-title":"A comprehensive review on ensemble deep learning: opportunities and challenges","volume":"35","author":"Mohammed","year":"2023","journal-title":"J. King Saud Univ. Comput. Inf. Sci"},{"key":"B18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/MilCIS.2015.7348942","article-title":"\u201cUnsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set),\u201d","volume-title":"2015 Military Communications and Information Systems Conference (MilCIS)","author":"Moustafa","year":"2015"},{"key":"B19","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","article-title":"A survey of network-based intrusion detection data sets","volume":"86","author":"Ring","year":"2019","journal-title":"Comput. Secur"},{"key":"B20","doi-asserted-by":"crossref","DOI":"10.1109\/ITMS52826.2021.9615321","article-title":"\u201cA literature review of machine learning techniques for cybersecurity in data centers,\u201d","volume-title":"ITMS 2021 - 2021 62nd International Scientific Conference on Information Technology and Management Science of Riga Technical University, Proceedings","author":"Roponena","year":"2021"},{"key":"B21","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ITMS56974.2022.9937116","article-title":"\u201cClassifier selection for an ensemble of network traffic analysis machine learning models,\u201d","volume-title":"2022 63rd International Scientific Conference on Information Technology and Management Science of Riga Technical University (ITMS)","author":"Roponena","year":"2022"},{"key":"B22","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ITMS64072.2024.10741602","article-title":"\u201cNetflow anomaly detection dataset creation for traffic analysis,\u201d","volume-title":"2024 IEEE 65th International Scientific Conference on Information Technology and Management Science of Riga Technical University (ITMS)","author":"Roponena","year":"2024"},{"key":"B23","author":"Rossum","year":"2009","journal-title":"Python 3 Reference Manual"},{"key":"B24","first-page":"117","article-title":"\u201cNetflow datasets for machine learning-based network intrusion detection systems,\u201d","volume-title":"Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST, volume 371 LNICST","author":"Sarhan","year":"2021"},{"key":"B25","doi-asserted-by":"crossref","DOI":"10.5220\/0006639801080116","article-title":"\u201cToward generating a new intrusion detection dataset and intrusion traffic characterization,\u201d","volume-title":"International Conference on Information Systems Security and Privacy","author":"Sharafaldin","year":"2018"},{"key":"B26","volume-title":"Sparkr: R Front End for \u2018Apache Spark'","year":"2024"},{"key":"B27","first-page":"9","volume-title":"Chapter 2 - Probability and Stochastic Processes","author":"Theodoridis","year":"2015"},{"key":"B28","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1038\/s41592-019-0686-2","article-title":"Scipy 1.0: fundamental algorithms for scientific computing in python","volume":"17","author":"Virtanen","year":"2020","journal-title":"Nat. Methods"},{"key":"B29","first-page":"1","volume-title":"Introduction to Design Science Research","author":"vom Brocke","year":"2020"},{"key":"B30","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1016\/j.ijhcs.2019.05.005","article-title":"Moving from a \u2018human-as-problem' to a \u2018human-as-solution' cybersecurity mindset","volume":"131","author":"Zimmermann","year":"2019","journal-title":"Int. J. Hum.-Comput. Stud"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1676362\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T07:05:55Z","timestamp":1762153555000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1676362\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,3]]},"references-count":30,"alternative-id":["10.3389\/fcomp.2025.1676362"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2025.1676362","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,3]]},"article-number":"1676362"}}