High Impact Factor : 4.396 icon | Submit Manuscript Online icon |

A Review on LAN and Router Anomaly Detection Using Machine Learning Techniques on the UNSW-NB15 Dataset

Author(s):

Deepanjali Kale , Siddhant College of Engineering, Sudumbare, Pune, Maharshtra, India-412109; Mairaj Inamdar, Siddhant College of Engineering, Sudumbare, Pune, Maharshtra, India-412109

Keywords:

LAN, Machine Learning, Deep Learning, CNN, Intrusion Detection

Abstract

Routers and local area networks serve as essential access points within contemporary communication systems, and because of this role, they are becoming more susceptible to sophisticated cyber-attacks, including reconnaissance, Denial of Service (DoS), exploits, malware spread, and botnet-driven intrusions. Traditional signature-based Intrusion Detection Systems (IDS) have shown limited effectiveness in detecting zero-day vulnerabilities and evolving attack patterns, highlighting the need for Machine Learning-based anomaly detection. The UNSW-NB15 dataset has recently gained recognition as a benchmark for evaluating machine learning-driven IDS models due to its realistic traffic composition and varied taxonomy of attacks, combined with a comprehensive feature set. This paper conducts a systematic review of machine learning-based, feature-engineering-focused, and hybrid IDS methodologies applied to the UNSW-NB15 dataset, particularly examining their appropriateness for deployment in LAN and router environments. The reviewed studies are assessed across critical methodological dimensions, including pre-processing workflows, feature selection methods, classifier design, evaluation metrics, and management of class imbalance. A thematic comparative analysis is provided across Decision Tree, Random Forest, SVM, Ensemble models, CNN variants, and feature-optimized pipelines to assess performance trends and computational trade-offs. Furthermore, the paper outlines significant research challenges, such as the misclassification of minority attacks, delays in inference, resource limitations in router platforms, incapacity for streaming and online learning, and restricted evaluation centred on deployment. In light of these findings, this review points to emerging avenues toward lightweight, feature-efficient, and deployment-oriented IDS frameworks that would be appropriate for real-time anomaly detection in LAN and router-based settings.

Other Details

Paper ID: IJSRDV14I10027
Published in: Volume : 14, Issue : 1
Publication Date: 01/04/2026
Page(s): 34-40

Article Preview

Download Article