27
(22 attacks and 1 for normal traffic) are encountered, whereas in the test set, there are 38
different labels, to make sure that the IDS can identify attacks that were not previously seen
during training, when it first encounters it during the validation of the model.
Figure 8: traffic distribution in training set
Figure 9: traffic distribution in test set