# PreProcessing Data

Loading the data: It loads test and training datasets from CSV files.

Removing missing values: It replaces missing values (denoted as '-') with NaN and then removes any rows containing NaN values in both training and test data.
    
Handling categorical mismatches: It ensures that only the categories present in both the training and test datasets are kept. This addresses the issue where the categorical values in the training data may not exactly match those in the test data.

In [1]:
import pandas as pd
import numpy as np 

#Load data from the provided csv's
test_data = pd.read_csv('cyber-data/UNSW_NB15_testing-set.csv')
train_data = pd.read_csv('cyber-data/UNSW_NB15_training-set.csv')

#This combines the data in order to make sure the column names are the same, and then it gets the list of columns to iterate over
combined_data = pd.concat([train_data, test_data])
cols = list(combined_data)

#This gets rid of all the empty values by replacing them with nulls, then dropping them using np.nan
for col in cols:
    train_data[col].replace('-', np.nan, inplace=True)
    train_data.dropna(subset=[col], inplace=True)
    test_data[col].replace('-', np.nan, inplace=True)
    test_data.dropna(subset=[col], inplace=True)

#This iterates over all the columns and only saves the categorical values that are in both datasets
for col in cols:
    train_data = train_data[train_data[col].isin(test_data[col])]
    test_data = test_data[test_data[col].isin(train_data[col])]

display(train_data)
display(test_data)

Unnamed: 0,id,dur,proto,service,state,spkts,dpkts,sbytes,dbytes,rate,...,ct_dst_sport_ltm,ct_dst_src_ltm,is_ftp_login,ct_ftp_cmd,ct_flw_http_mthd,ct_src_ltm,ct_srv_dst,is_sm_ips_ports,attack_cat,label
214,215,0.001146,udp,dns,CON,2,2,146,178,2617.801058,...,2,3,0,0,0,2,8,0,Normal,0
241,242,0.001066,udp,dns,CON,2,2,146,178,2814.258996,...,1,4,0,0,0,5,5,0,Normal,0
255,256,0.001169,udp,dns,CON,2,2,132,164,2566.295861,...,1,1,0,0,0,1,4,0,Normal,0
293,294,0.001106,udp,dns,CON,2,2,132,164,2712.477299,...,1,1,0,0,0,2,3,0,Normal,0
295,296,0.001140,udp,dns,CON,2,2,132,164,2631.579064,...,1,1,0,0,0,3,2,0,Normal,0
...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...
40889,40890,0.001006,udp,dns,CON,2,2,146,178,2982.107425,...,1,3,0,0,0,2,6,0,Normal,0
40901,40902,0.001016,udp,dns,CON,2,2,146,178,2952.755752,...,1,3,0,0,0,2,4,0,Normal,0
51762,51763,0.000010,udp,dhcp,INT,2,0,1152,0,100000.002500,...,4,4,0,0,0,4,3,0,Exploits,1
54783,54784,0.000010,udp,dhcp,INT,2,0,1152,0,100000.002500,...,4,4,0,0,0,4,3,0,Exploits,1


Unnamed: 0,id,dur,proto,service,state,spkts,dpkts,sbytes,dbytes,rate,...,ct_dst_sport_ltm,ct_dst_src_ltm,is_ftp_login,ct_ftp_cmd,ct_flw_http_mthd,ct_src_ltm,ct_srv_dst,is_sm_ips_ports,attack_cat,label
2847,2848,0.000008,udp,snmp,INT,2,0,136,0,125000.000300,...,1,1,0,0,0,1,1,0,Reconnaissance,1
10382,10383,0.000008,udp,snmp,INT,2,0,138,0,125000.000300,...,1,3,0,0,0,6,1,0,Reconnaissance,1
11758,11759,0.338518,tcp,http,FIN,66,14,78481,612,233.370165,...,1,1,0,0,1,1,1,0,Exploits,1
23378,23379,0.001110,udp,dns,CON,2,2,146,178,2702.702815,...,1,1,0,0,0,1,1,0,Normal,0
23412,23413,0.001017,udp,dns,CON,2,2,146,178,2949.852669,...,1,2,0,0,0,3,1,0,Normal,0
...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...
40280,40281,0.001064,udp,dns,CON,2,2,146,178,2819.548997,...,1,1,0,0,0,6,3,0,Normal,0
40281,40282,0.001147,udp,dns,CON,2,2,146,178,2615.518738,...,1,1,0,0,0,7,1,0,Normal,0
40288,40289,0.001000,udp,dns,CON,2,2,132,164,2999.999858,...,1,2,0,0,0,8,4,0,Normal,0
49522,49523,0.000004,udp,snmp,INT,2,0,136,0,250000.000600,...,1,1,0,0,0,1,1,0,Reconnaissance,1


# Encoding Categorical Features and Normalizing Numeric Features

This script uses OneHotEncoder to convert categorical columns to a format that can be provided to machine learning algorithms, and StandardScaler to normalize the numeric columns.

In [2]:
from sklearn.preprocessing import OneHotEncoder, StandardScaler
from sklearn.compose import ColumnTransformer
from sklearn.pipeline import Pipeline

# Identify categorical and numeric columns
categorical_cols = train_data.select_dtypes(include=['object']).columns
numeric_cols = train_data.select_dtypes(include=['number']).columns

# Create transformers for categorical and numeric data
categorical_transformer = Pipeline(steps=[
    ('onehot', OneHotEncoder(handle_unknown='ignore'))
])
numeric_transformer = Pipeline(steps=[
    ('scaler', StandardScaler())
])

# Combine transformers into a single preprocessor
preprocessor = ColumnTransformer(
    transformers=[
        ('cat', categorical_transformer, categorical_cols),
        ('num', numeric_transformer, numeric_cols)
    ])

# Apply transformations to both training and testing data
train_data_preprocessed = preprocessor.fit_transform(train_data)
test_data_preprocessed = preprocessor.transform(test_data)


# Adding Model Training with EarlyStopping and ModelCheckpoint

In [3]:
import tensorflow as tf

# Define a simple neural network model
model = tf.keras.Sequential([
    tf.keras.layers.Dense(128, activation='relu', input_shape=[train_data_preprocessed.shape[1]]),
    tf.keras.layers.Dense(1, activation='sigmoid')
])

# Compile the model
model.compile(optimizer='adam', loss='binary_crossentropy', metrics=['accuracy'])

# Setup EarlyStopping and ModelCheckpoint
early_stopping = tf.keras.callbacks.EarlyStopping(monitor='val_loss', patience=10)
model_checkpoint = tf.keras.callbacks.ModelCheckpoint(
    'best_model.h5', monitor='val_loss', save_best_only=True)

# Train the model
history = model.fit(
    train_data_preprocessed, 
    train_data['label'],  # 'label' is the target variable
    epochs=100,
    validation_split=0.2,
    callbacks=[early_stopping, model_checkpoint]
)


Epoch 1/100
Epoch 2/100

  saving_api.save_model(


Epoch 3/100
Epoch 4/100
Epoch 5/100
Epoch 6/100
Epoch 7/100
Epoch 8/100
Epoch 9/100
Epoch 10/100
Epoch 11/100
Epoch 12/100
Epoch 13/100
Epoch 14/100
Epoch 15/100
Epoch 16/100
Epoch 17/100
Epoch 18/100
Epoch 19/100
Epoch 20/100
Epoch 21/100
Epoch 22/100
Epoch 23/100
Epoch 24/100
Epoch 25/100
Epoch 26/100
Epoch 27/100
Epoch 28/100
Epoch 29/100
Epoch 30/100
Epoch 31/100
Epoch 32/100
Epoch 33/100
Epoch 34/100
Epoch 35/100
Epoch 36/100
Epoch 37/100
Epoch 38/100
Epoch 39/100
Epoch 40/100
Epoch 41/100
Epoch 42/100
Epoch 43/100
Epoch 44/100
Epoch 45/100
Epoch 46/100
Epoch 47/100
Epoch 48/100
Epoch 49/100
Epoch 50/100
Epoch 51/100
Epoch 52/100
Epoch 53/100
Epoch 54/100
Epoch 55/100
Epoch 56/100
Epoch 57/100
Epoch 58/100
Epoch 59/100
Epoch 60/100
Epoch 61/100
Epoch 62/100
Epoch 63/100
Epoch 64/100
Epoch 65/100
Epoch 66/100
Epoch 67/100
Epoch 68/100
Epoch 69/100
Epoch 70/100
Epoch 71/100
Epoch 72/100
Epoch 73/100
Epoch 74/100
Epoch 75/100
Epoch 76/100
Epoch 77/100
Epoch 78/100
Epoch 79/100
Epoch 