vanderbilt-ml / 51-boyce-mlproj-NIDS

1 stars 0 forks source link

Model fitting and evaluation #7

Open vanderryan opened 2 years ago

vanderryan commented 2 years ago

List 1-3 assumptions about feature importance or how you anticipate the model to perform.

vanderryan commented 2 years ago
  1. the L7_PROTO will be an important feature as certain protocols are at higher risk of exploit
  2. If able to create a time metric, that will be valuable to see when attacks are real (i.e. attacks during 'working hours' are likely so as to blend in with regular traffic or exploit system users who are working)
  3. Precision of True Positives is preferred to be over 60%