Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Explainable Anomaly Detection in Encrypted Network Traffic Using Data Analytics

View through CrossRef
The unsanctioned growth of the encrypted network traffic is a two-sided problem for the cybersecurity, on one hand, it preserves the privacy of the users, and, on the other hand, it obscures the malicious motive of the traditional intrusion detection systems. The current paper presents this challenge by the construction of a model of the encrypted traffic data anomaly that can be explained in data analytics. The solution proposed includes the classical machine learning (Random Forests, Support Vector Machines), deep learning (Autoencoders, LSTMs) algorithms, and explainability (SHAP, LIME, counterfactual analysis). This framework was tested and trained with several benchmark networks (CICIDS2017, ISCX VPN/Tor, UNSW-NB15) and guarantees the universality of the framework in different network settings. The findings show that the accuracy and recall of deep learning models can outperform those of hybrids, but hybrid ensembles (e.g., RF + Autoencoder) can be more accurate because they do not weaken the performance identified by them, but on the contrary, enhance their interpretability. Explainability profiling revealed that time spent in a flow, packets inter-arrival variance, and bytes distribution are the critical characteristics of traffic that are relevant in differentiating a deviant behavior and an ordinary encrypted traffic. The system has already been found to be practically applicable in case study of enterprise and IoT and telecom networks. In addition, explainable AI implementation will lead to improved trust in the analyst, regulatory bodies, and reduce ethical issues regarding black-box detection systems. The results show that accuracy and transparency ought to be an element of cybersecurity. Directions Future Future Future directions involve the application of federated learning to carry out privacy-preserving detection, real time explainability dashboards, standard controlled encrypted traffic benchmarks, and graph-based anomaly detection. The given work is a viable and efficient solution for anomaly detection in an encrypted space that contributes to the development of both technical and ethical components of the cybersecurity sector.
Title: Explainable Anomaly Detection in Encrypted Network Traffic Using Data Analytics
Description:
The unsanctioned growth of the encrypted network traffic is a two-sided problem for the cybersecurity, on one hand, it preserves the privacy of the users, and, on the other hand, it obscures the malicious motive of the traditional intrusion detection systems.
The current paper presents this challenge by the construction of a model of the encrypted traffic data anomaly that can be explained in data analytics.
The solution proposed includes the classical machine learning (Random Forests, Support Vector Machines), deep learning (Autoencoders, LSTMs) algorithms, and explainability (SHAP, LIME, counterfactual analysis).
This framework was tested and trained with several benchmark networks (CICIDS2017, ISCX VPN/Tor, UNSW-NB15) and guarantees the universality of the framework in different network settings.
The findings show that the accuracy and recall of deep learning models can outperform those of hybrids, but hybrid ensembles (e.
g.
, RF + Autoencoder) can be more accurate because they do not weaken the performance identified by them, but on the contrary, enhance their interpretability.
Explainability profiling revealed that time spent in a flow, packets inter-arrival variance, and bytes distribution are the critical characteristics of traffic that are relevant in differentiating a deviant behavior and an ordinary encrypted traffic.
The system has already been found to be practically applicable in case study of enterprise and IoT and telecom networks.
In addition, explainable AI implementation will lead to improved trust in the analyst, regulatory bodies, and reduce ethical issues regarding black-box detection systems.
The results show that accuracy and transparency ought to be an element of cybersecurity.
Directions Future Future Future directions involve the application of federated learning to carry out privacy-preserving detection, real time explainability dashboards, standard controlled encrypted traffic benchmarks, and graph-based anomaly detection.
The given work is a viable and efficient solution for anomaly detection in an encrypted space that contributes to the development of both technical and ethical components of the cybersecurity sector.

Related Results

The Burden of Road Traffic Injuries: A Global Perspective
The Burden of Road Traffic Injuries: A Global Perspective
Introduction     Road Traffic Injury (RTI) pose a significant health challenge. It represents the eighth leading cause of death globally, prompting the UN to designate 2011-2020 as...
Novel traffic congestion detection algorithms for smart city applications
Novel traffic congestion detection algorithms for smart city applications
Summary Traffic congestion detection (TCD) techniques are becoming a critical component of traffic management systems. They can be considered a pre‐step to addres...
Bootstrap Forest based method for Encrypted Network Traffic Analysis
Bootstrap Forest based method for Encrypted Network Traffic Analysis
Encrypting communications and data over the Internet becomes essential in ensuring the privacy of communications and protecting the data from increasing threats. Hence, majority of...
Anomaly detection in encrypted HTTPS traffic using machine learning: a comparative analysis of feature selection techniques
Anomaly detection in encrypted HTTPS traffic using machine learning: a comparative analysis of feature selection techniques
With the increasing use of encryption in network traffic, anomaly detection in encrypted traffic has become a challenging problem. This study proposes an approach for anomaly detec...
Network Traffic Prediction Based on Boosting Learning
Network Traffic Prediction Based on Boosting Learning
Classification of network traffic is an important topic for network management, traffic routing, safe traffic discrimination, and better service delivery. Traffic examination is th...
Introduction to Artificial Intelligence in Traffic Systems
Introduction to Artificial Intelligence in Traffic Systems
Traffic management is a pressing challenge in modern societies. The population of humans is increasing at a substantial pace, and along with that, the expanse of urban areas and th...

Back to Top