Network Intrusion Detection Using SNMP MIB Data: A Multi-Device Machine Learning Approach
Abstract
The increasing complexity and volume of network traffic have made the accurate and timely detection of cyber-attacks a critical challenge. This study proposes a machine learning-based intrusion detection approach using Simple Network Management Protocol - Management Information Base (SNMP-MIB) data collected from four different switching devices in a university network infrastructure. The proposed approach models network behavior by extracting statistical traffic features from MIB and Remote Monitoring (RMON) objects and applying multiple classification algorithms, including Random Forest, XGBoost, Support Vector Machine, Decision Tree, Gradient Boosting, and Extra Trees. To address class imbalance, different sampling strategies, including no sampling, SMOTE, and under-sampling, are evaluated. Furthermore, a cross-device evaluation strategy is implemented to assess the model's generalization capability across different network devices. Experimental results demonstrate that ensemble-based methods, particularly Extra Trees and Random Forest, achieve superior performance. Overall, the findings indicate that SNMP-based anomaly detection can achieve high accuracy and strong generalization across devices. This study highlights the effectiveness, reliability, and device-independent capability of machine learning models for network multi-class classification.