Seena K R
Vol. 7, Issue 1, Jan-Dec 2021
Page Number: 295 - 308
Abstract:
Cybersecurity systems deal with a huge amount of data like network traffic, system logs, user login records, and information from devices. Because of this, it's hard to monitor everything by hand or use old rules to catch security threats. Newer systems that use machine learning have shown promise, but most of them rely on labeled data, which is costly to create, quickly becomes outdated, and doesn't cover new or unknown attacks well. Self-supervised learning offers a better way. It learns from large amounts of data that hasn’t been labeled, using automatically created learning goals. Recent studies show that contrastive self-supervised learning can find unusual activity in encrypted network traffic without looking at the actual content of the packets. This research introduces a new framework called SS-CADF, which uses unlabeled traffic data to learn what normal and abnormal network behavior looks like. The framework will use several techniques: transforming features, learning patterns over time, contrastive learning, and scoring for anomalies. Features like packet size, how long a connection lasts, times between packets, the type of protocol used, and details about the source and destination will be used to build training examples. An encoder based on Transformer or LSTM models will create hidden representations of the data. Contrastive learning will help the model recognize similar and different traffic patterns. Then, an anomaly score will be calculated based on these representations. The framework will be tested using standard cybersecurity datasets such as CICIDS2017, UNSW-NB15, CIC-Darknet2020, and possibly encrypted traffic datasets. Its performance will be measured using accuracy, precision, recall, F1 score, ROC-AUC, PR-AUC, false-positive rate, and how well it detects new attacks. The goal is to create a scalable and efficient system that can find new and unknown attack patterns without needing labeled data.
Disclaimer: Indexing of published papers is subject to the evaluation and acceptance criteria of the respective indexing agencies. While we strive to maintain high academic and editorial standards, International Journal of Innovations in Applied Sciences and Engineering does not guarantee the indexing of any published paper. Acceptance and inclusion in indexing databases are determined by the quality, originality, and relevance of the paper, and are at the sole discretion of the indexing bodies.