错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Artificial Intelligence-Based Approaches for Anomaly Detection

  • Aswani Kumar Cherukuri,
  • Sumaiya Thaseen Ikram,
  • Gang Li,
  • Xiao Liu

摘要

The complexity of traffic analysis has increased due to the increase in network traffic and the deployment of various online applications. The limitation with traditional methods such as payload, deep packet inspection and statistical approaches is the dependency for feature engineering and cannot perform encrypted traffic classification. Hence, machine learning (ML) and deep learning (DL) methods are widely used for encrypted traffic analysis. These models are superior in automating threat detection with increase in performance. This chapter discusses various machine learning and deep learning-based encrypted traffic analysis in detail. In addition, two models have been presented in this chapter. The first model detects Darknet traffic using the AdaBoost classifier on the CIC-Darknet2020 dataset. Experimental analysis shows superior performance on accuracy, precision, recall and F-score. The second model is Explainable Boosting Machine (EBM) using Explainable Artificial Intelligence (XAI) to classify the encrypted traffic of CSE-CIC-IDS2018 dataset. The results show that EBM outperformed other models like Random Forest (RF) and Light Gradient Boosting (LGB).