Method for detecting unauthorized influences in the process of network interaction based on intelligent traffic analysis

Skladannyi, Pavlo та Kostiuk, Yuliia та Bebeshko, Bohdan та Hulak, Hennadii та Astapenya, Volodymyr (2026) Method for detecting unauthorized influences in the process of network interaction based on intelligent traffic analysis Cyber Security and Data Protection 2026, 4223. с. 127-153. ISSN 1613-0073

[thumbnail of P_Skladannyi_Y_Kostiuk_B_Bebeshko_H_Hulak_V_Astapenia_CSDP_4223_FITM.pdf] Текст
P_Skladannyi_Y_Kostiuk_B_Bebeshko_H_Hulak_V_Astapenia_CSDP_4223_FITM.pdf

Download (1MB)
Офіційне посилання: https://ceur-ws.org/Vol-4223/

Анотація

Modern network infrastructure is characterized by high heterogeneity, scalability, and complexity, which complicate ensuring stable operation in the face of dynamic threats. In particular, unauthorized influences pose a special danger ‒ hidden or undeclared actions that traditional signature analysis methods cannot detect. This article proposes a method for detecting unauthorized influences in network interactions based on intelligent traffic analysis. The problem lies in the insufficient effectiveness of traditional methods in detecting new or hidden attacks. The study aims to develop a hybrid approach that combines traffic clustering, analytical indices, and eXplainable Artificial Intelligence (XAI). Self-Organizing Maps (SOMs) are used for traffic cluster analysis, and a criticality index and derivative are used to assess the impact of features. SHAP and LIME methods are used to interpret the results. Experiments are conducted on realworld network datasets. Improvements in accuracy metrics (F1, TPR, MCC) are obtained compared to baseline models. The scientific novelty lies in the combination of SOM clustering with index-based impact assessment and explainable traffic analysis. The method is suitable for implementation in intrusion detection systems and for improving the resilience of corporate networks to atypical threats

Тип елементу : Стаття
Ключові слова: explainable artificial intelligence; XAI; self-organizing map. SOM; network traffic anomaly detection; cyber influence modeling; intelligent intrusion detection; critical feature analysis; cyber threats; unsupervised learning
Типологія: Статті у базах даних > Scopus (без квартилю)
Підрозділи: Факультет інформаційних технологій та математики > Кафедра інформаційної та кібернетичної безпеки ім. професора Володимира Бурячка
Користувач, що депонує: Павло Миколайович Складанний
Дата внесення: 19 Серп 2026 08:13
Останні зміни: 19 Серп 2026 08:13
URI: https://elibrary.kubg.edu.ua/id/eprint/59389

Actions (login required)

Перегляд елементу Перегляд елементу