Javascript must be enabled to continue!
Explainable Anomaly Detection in Encrypted Network Traffic Using Data Analytics
View through CrossRef
The unsanctioned growth of the encrypted network traffic is a two-sided problem for the cybersecurity, on one hand, it preserves the privacy of the users, and, on the other hand, it obscures the malicious motive of the traditional intrusion detection systems. The current paper presents this challenge by the construction of a model of the encrypted traffic data anomaly that can be explained in data analytics. The solution proposed includes the classical machine learning (Random Forests, Support Vector Machines), deep learning (Autoencoders, LSTMs) algorithms, and explainability (SHAP, LIME, counterfactual analysis). This framework was tested and trained with several benchmark networks (CICIDS2017, ISCX VPN/Tor, UNSW-NB15) and guarantees the universality of the framework in different network settings. The findings show that the accuracy and recall of deep learning models can outperform those of hybrids, but hybrid ensembles (e.g., RF + Autoencoder) can be more accurate because they do not weaken the performance identified by them, but on the contrary, enhance their interpretability. Explainability profiling revealed that time spent in a flow, packets inter-arrival variance, and bytes distribution are the critical characteristics of traffic that are relevant in differentiating a deviant behavior and an ordinary encrypted traffic. The system has already been found to be practically applicable in case study of enterprise and IoT and telecom networks. In addition, explainable AI implementation will lead to improved trust in the analyst, regulatory bodies, and reduce ethical issues regarding black-box detection systems. The results show that accuracy and transparency ought to be an element of cybersecurity. Directions Future Future Future directions involve the application of federated learning to carry out privacy-preserving detection, real time explainability dashboards, standard controlled encrypted traffic benchmarks, and graph-based anomaly detection. The given work is a viable and efficient solution for anomaly detection in an encrypted space that contributes to the development of both technical and ethical components of the cybersecurity sector.
Al-Kindi Center for Research and Development
Title: Explainable Anomaly Detection in Encrypted Network Traffic Using Data Analytics
Description:
The unsanctioned growth of the encrypted network traffic is a two-sided problem for the cybersecurity, on one hand, it preserves the privacy of the users, and, on the other hand, it obscures the malicious motive of the traditional intrusion detection systems.
The current paper presents this challenge by the construction of a model of the encrypted traffic data anomaly that can be explained in data analytics.
The solution proposed includes the classical machine learning (Random Forests, Support Vector Machines), deep learning (Autoencoders, LSTMs) algorithms, and explainability (SHAP, LIME, counterfactual analysis).
This framework was tested and trained with several benchmark networks (CICIDS2017, ISCX VPN/Tor, UNSW-NB15) and guarantees the universality of the framework in different network settings.
The findings show that the accuracy and recall of deep learning models can outperform those of hybrids, but hybrid ensembles (e.
g.
, RF + Autoencoder) can be more accurate because they do not weaken the performance identified by them, but on the contrary, enhance their interpretability.
Explainability profiling revealed that time spent in a flow, packets inter-arrival variance, and bytes distribution are the critical characteristics of traffic that are relevant in differentiating a deviant behavior and an ordinary encrypted traffic.
The system has already been found to be practically applicable in case study of enterprise and IoT and telecom networks.
In addition, explainable AI implementation will lead to improved trust in the analyst, regulatory bodies, and reduce ethical issues regarding black-box detection systems.
The results show that accuracy and transparency ought to be an element of cybersecurity.
Directions Future Future Future directions involve the application of federated learning to carry out privacy-preserving detection, real time explainability dashboards, standard controlled encrypted traffic benchmarks, and graph-based anomaly detection.
The given work is a viable and efficient solution for anomaly detection in an encrypted space that contributes to the development of both technical and ethical components of the cybersecurity sector.
Related Results
The Burden of Road Traffic Injuries: A Global Perspective
The Burden of Road Traffic Injuries: A Global Perspective
Introduction Road Traffic Injury (RTI) pose a significant health challenge. It represents the eighth leading cause of death globally, prompting the UN to designate 2011-2020 as...
ecision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predi
ecision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predictive Analytics in Precision Farming and Predi
The scope of sensor networks and the Internet of Things spanning rapidly to diversified domains but not limited to sports, health, and business trading. In recent past, the sensors...
Novel traffic congestion detection algorithms for smart city applications
Novel traffic congestion detection algorithms for smart city applications
Summary
Traffic congestion detection (TCD) techniques are becoming a critical component of traffic management systems. They can be considered a pre‐step to addres...
Bootstrap Forest based method for Encrypted Network Traffic Analysis
Bootstrap Forest based method for Encrypted Network Traffic Analysis
Encrypting communications and data over the Internet becomes essential in ensuring the privacy of communications and protecting the data from increasing threats. Hence, majority of...
Anomaly detection in encrypted HTTPS traffic using machine learning: a comparative analysis of feature selection techniques
Anomaly detection in encrypted HTTPS traffic using machine learning: a comparative analysis of feature selection techniques
With the increasing use of encryption in network traffic, anomaly detection in encrypted traffic has become a challenging problem. This study proposes an approach for anomaly detec...
Network Traffic Prediction Based on Boosting Learning
Network Traffic Prediction Based on Boosting Learning
Classification of network traffic is an important topic for network management, traffic routing, safe traffic discrimination, and better service delivery. Traffic examination is th...
Harnessing Artificial Intelligence for Road Traffic Surveillance: A Comprehensive Overview of AIbased Statistical Models for Traffic Monitoring and Flow Prediction
Harnessing Artificial Intelligence for Road Traffic Surveillance: A Comprehensive Overview of AIbased Statistical Models for Traffic Monitoring and Flow Prediction
AI-based road traffic surveillance has dramatically changed traffic system
monitoring, analytics, and management. Torn between the inefficiencies of traffic
management techniques a...
Introduction to Artificial Intelligence in Traffic Systems
Introduction to Artificial Intelligence in Traffic Systems
Traffic management is a pressing challenge in modern societies. The
population of humans is increasing at a substantial pace, and along with that, the
expanse of urban areas and th...

