hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Privacy-Preserving Anomaly Detection in Encrypted Traffic
Halmstad University, School of Information Technology.
Halmstad University, School of Information Technology.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In 2023, 90% of internet traffic was encrypted which blocked forensic analysis without opening the packets. Our thesis develops a method for the identification of suspicious behavior in encrypted traffic on the basis of metadata, without breaking privacy laws including GDPR. Four machine learning algorithms were experimented with for anomaly detection: Isolation Forest, One-Class SVM, DBSCAN, and K-Means. Based on the results, Isolation Forest was selected for the final system due to its superior performance (AUC = 0.94, AP = 0.36). We have developed thirteen visualizations including scatter plots and performance charts, to clearly show the results, and finally with the help of seven peers in network forensics we reviewed these plots to find the better solution. Our system can be used in Security Operations Centers (SOC) and it will be helpful in investigating threats such as data theft while protecting privacy. Our system will provide accuracy, clarity and legal compliance. 

Keywords: Encrypted Traffic, Digital Forensics, Machine Learning, Anomaly Detection, PCA, DBSCAN, Isolation Forest, Interactive Visualization

Place, publisher, year, edition, pages
2025. , p. 42
Keywords [en]
Encrypted Traffic, Digital Forensics, Machine Learning, Anomaly Detection, PCA, DBSCAN, Isolation Forest, Interactive Visu- alization
National Category
Other Computer and Information Science
Identifiers
URN: urn:nbn:se:hh:diva-56267OAI: oai:DiVA.org:hh-56267DiVA, id: diva2:1965964
Educational program
Master's Programme in Network Forensics, 60 credits
Presentation
2025-05-15, Halmstad University, 10:00 (English)
Supervisors
Examiners
Available from: 2025-06-11 Created: 2025-06-09 Last updated: 2025-10-01Bibliographically approved

Open Access in DiVA

fulltext(1778 kB)99 downloads
File information
File name FULLTEXT02.pdfFile size 1778 kBChecksum SHA-512
7ab5c228c0eedd3809e3eb78b3820caeb78697d20bdc8cf03b9b693b111bd70d6927df45beeade1257a31d80b6ddaf01947e9e006d058ad8fb74a13e15d46f25
Type fulltextMimetype application/pdf

By organisation
School of Information Technology
Other Computer and Information Science

Search outside of DiVA

GoogleGoogle Scholar
Total: 99 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 261 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf