arXiv:2606. 29797v1 Announce Type: cross Abstract: Machine learning network intrusion detection systems (IDS) rely on aggregate flow statistics that discard distributional structure, while established entropy measures require raw packet sequences unavailable in pre-aggregated flow datasets.
By Mohamed Aly Bouke, Md Shohel Sayeed, Swee-Huay Heng, Azizol Abdullah, Mohamed Othman
Machine learning network intrusion detection systems (IDS) rely on aggregate flow statistics that discard distributional structure, while established entropy measures require raw packet sequences unavailable in pre-aggregated flow datasets. We propose Multi-Level Distributional Entropy (MDE), an analytical framework that derives interpretable entropy features directly from flow-level summary statistics at three levels: within-flow Gaussian differential entropy, cross-directional Jensen-Shannon divergence (JSD), and Transmission Control Protocol (TCP) flag-pattern Shannon entropy, without raw packet access or training data.
arXiv:2609.36167v1 Announce Type: cross
Abstract: Distributed Denial of Service attacks are a growing threat to network infrastructure, and new techniques, including the use of generative AI, make th...
By Aadith Sukumar, Isha Singh, Devershika Mohane, Ankit Mukherjee, Ankush Dutta, Rahee Walambe, Ketan Kotecha
arXiv:2608.22075v2 Announce Type: replace-cross
Abstract: Adversaries now move faster than manual response processes can absorb. The average eCrime breakout time, that is, the interval between initia...
By Alexandre Amaral, Fernando Moro, Ana Malheiro
arXiv:2504. 01882v2 Announce Type: replace Abstract: The use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques.
By Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos Garcia-Rubio, Rebeca P. D\'iaz-Redondo, Celeste Campo, Ana Fern\'andez-Vilas, Manuel Fern\'andez-Veiga
The paper introduces a GAN‑based framework for detecting DDoS attacks that are designed to evade traditional security systems. It combines Random Forests, Deep Neural Ensembles, and Transformer models trained on the CICDDoS2019 dataset with synthetic adversarial traffic generated by a WGAN‑GP. Experiments show that this hybrid training significantly improves detection accuracy and resilience against unseen adversarial traffic, and real‑world tests confirm its practical effectiveness.
By Makram Chehayeb, Walid Fahs, Amina Rizk, Rida Khatoun, Omran Berjawi
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv:2608. 00118v1 Announce Type: cross Abstract: Cybersecurity is a fundamental requirement for protecting wearable devices used in healthcare Internet of Things (H-IoT) systems.
By Mirza Akhi
arXiv:2606. 00155v1 Announce Type: cross Abstract: Modern network intrusion detection systems (NIDS) are caught in a structural contradiction: the protocols carrying the highest threat intelligence are precisely those encrypted under TLS 1.
By Vivek Kumar Sharma
arXiv:2607. 15379v1 Announce Type: cross Abstract: Network anomaly detection is increasingly challenging due to the growing diversity and variability of traffic patterns, which are not always well captured by traditional statistical features.
By Iuri Mundstock, Abreu Quevedo, J\'eferson Campos Nobre, Roben C. Lunardi, Thiago L. T. da Silveira, Bruno L. Dalmazo
arXiv:2503. 17867v3 Announce Type: replace-cross Abstract: Distributed Denial of Service attacks represent an active cybersecurity research problem.
By Alexandru Apostu, Silviu Gheorghe, Andrei H\^iji, Nicolae Cleju, Andrei P\u{a}tra\c{s}cu, Cristian Rusu, Radu Ionescu, Paul Irofti