Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Artificial Intelligence-Based Anomaly Detection Technology over Encrypted Traffic: A Systematic Literature Reviewopen access

Authors
Ji, Il HwanLee, Ju HyeonKang, Min JiPark, Woo JinJeon, Seung HoSeo, Jung Taek
Issue Date
Feb-2024
Publisher
MDPI
Keywords
cyber security; anomaly detection; encrypted traffic
Citation
SENSORS, v.24, no.3
Journal Title
SENSORS
Volume
24
Number
3
URI
https://scholarworks.bwise.kr/gachon/handle/2020.sw.gachon/90615
DOI
10.3390/s24030898
ISSN
1424-8220
1424-3210
Abstract
As cyber-attacks increase in unencrypted communication environments such as the traditional Internet, protected communication channels based on cryptographic protocols, such as transport layer security (TLS), have been introduced to the Internet. Accordingly, attackers have been carrying out cyber-attacks by hiding themselves in protected communication channels. However, the nature of channels protected by cryptographic protocols makes it difficult to distinguish between normal and malicious network traffic behaviors. This means that traditional anomaly detection models with features from packets extracted a deep packet inspection (DPI) have been neutralized. Recently, studies on anomaly detection using artificial intelligence (AI) and statistical characteristics of traffic have been proposed as an alternative. In this review, we provide a systematic review for AI-based anomaly detection techniques over encrypted traffic. We set several research questions on the review topic and collected research according to eligibility criteria. Through the screening process and quality assessment, 30 research articles were selected with high suitability to be included in the review from the collected literature. We reviewed the selected research in terms of dataset, feature extraction, feature selection, preprocessing, anomaly detection algorithm, and performance indicators. As a result of the literature review, it was confirmed that various techniques used for AI-based anomaly detection over encrypted traffic were used. Some techniques are similar to those used for AI-based anomaly detection over unencrypted traffic, but some technologies are different from those used for unencrypted traffic.
Files in This Item
There are no files associated with this item.
Appears in
Collections
ETC > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher SEO, JUNGTAEK photo

SEO, JUNGTAEK
College of IT Convergence (컴퓨터공학부(스마트보안전공))
Read more

Altmetrics

Total Views & Downloads

BROWSE