Giampaolo Bovenzi

dblp:248/8401 · DBLP profile ↗
← Back
22ranked-venue papers
8as first author
21since 2021 · last 2026
0000-0002-0997-9724ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 5 first-author · 15 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Cross-network transferability of AI-based network intrusion detection systems in heterogeneous Internet of Things environments
abstract
The rapid expansion of Internet of Things (IoT) ecosystems has amplified the demand for robust cybersecurity solutions, with Artificial Intelligence (AI)-based Network Intrusion Detection System (NIDS) emerging as a promising component of modern defense strategies. Despite their strong performance when trained and evaluated on traffic collected within the same IoT environment, a critical open question remains: can these systems transfer effectively when deployed in different IoT networks? In this work, we present a comprehensive experimental study evaluating the cross-network transferability of AI-based NIDS built using Machine Learning (ML) and Deep Learning (DL), including attention-based architectures. Our analysis spans eight heterogeneous IoT network environments, represented by publicly available datasets. Specifically, we ( i ) assess attack-level transferability across networks, ( i i ) quantify the impact of feature informativeness on cross-network performance, ( i i i ) leverage eXplainable Artificial Intelligence (XAI) to interpret decisions in cross-network scenarios, ( i v ) investigate design principles for universal NIDS, and ( v ) evaluate edge-device deployment feasibility. Our findings provide systematic insight into the limits of AI-driven NIDS. Notably, cross-network transferability is highly variable and strongly influenced by attack semantics and dataset characteristics: volumetric attacks transfer effectively, whereas others remain dataset-dependent. Transferability benefits from generalizable feature design and multi-domain training, yet universal robustness remains challenging. Finally, while edge deployment is feasible from a memory perspective, Convolutional Neural Network (CNN) architectures offer substantially lower inference latency than Transformers on resource-constrained devices.
Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè
Comput. Networks2
2026 A multimodal and perturbation-aware learning approach for robust traffic classification
abstract
Traffic Classification (TC) is pivotal for network management, cybersecurity, and Quality of Experience (QoE) monitoring. However, while Deep Learning (DL) has significantly advanced TC, most existing works assume static, idealized conditions, overlooking key challenges of real-world deployments—such as traffic variability, routing asymmetries, out-of-order packet arrivals, and partial visibility at the Vantage Points (VPs). This motivates the need for robustness evaluations under such scenarios. In this work, we investigate the robustness of state-of-the-art (SOTA) TC models under realistic, yet controlled, perturbation scenarios. Specifically, we introduce novel, model-agnostic traffic perturbations—simulating time jitter, retransmissions, and partial visibility—to reflect conditions commonly encountered in live network traffic. We evaluate our approach on three public datasets—i.e., VPN-16 , MIRAGE-19 , and MIRAGE-24 —and show how Mimetic-Enhanced , a multimodal model, tends to outperform two representative single-modal counterparts both in terms of TC effectiveness on clean traffic and robustness under perturbations. Nonetheless, our analysis also reveals that multimodal models remain vulnerable under specific perturbation settings. To address this limitation, we propose a model-agnostic perturbation-aware training framework based on Supervised Data Augmentation ( Aug ) and Contrastive Learning ( CL )—considering both self-supervised and supervised variants. Unlike architecture-specific solutions, our approach operates at the learning strategy level , allowing it to be seamlessly applied to diverse classifiers without requiring structural modifications. Adopting Mimetic-Enhanced as a primary multimodal case study, we integrate the proposed strategies into its two-stage training pipeline. Experimental results demonstrate that perturbation-aware training not only improves TC effectiveness on clean (i.e., unperturbed) traffic—particularly when applied across both training stages—but also significantly strengthens the model’s robustness under diverse and realistic perturbation scenarios. Furthermore, we investigate Out-of-Distribution (OOD) detection, model calibration, and TC effectiveness in low-data regimes. Finally, we explicitly demonstrate the framework’s generalizability by validating it on other SOTA architectures, spanning both single- and multi-modal approaches.
Idio Guarino, Giampaolo Bovenzi, Alfredo Nascita, Domenico Ciuonzo, Damiano Carra, Antonio Pescapè
Comput. Networks2
2026 Analyzing the impact of shifts in encrypted mobile-app traffic on multimodal few-shot learning
abstract
Network management is essential for ensuring efficient and secure Internet operations, with traffic classification serving as a core element. Currently, traffic classification is facing increasing challenges due to the growing presence of highly dynamic mobile-app traffic , being fueled by the continuous release of new apps, frequent updates, evolving communication patterns, and stricter encrypted protocols. These shifts can significantly alter traffic patterns, making it difficult to keep state-of-the-art machine and deep learning-based traffic classifiers up to date, due to the severe lack of current, high-quality traffic datasets needed to train and adapt such data-driven models. Few-Shot Learning ( FSL ) offers a promising solution by enabling classification even when only a limited amount of labeled traffic data is available. However, the investigation of FSL in the domain of traffic classification is still in its early stages, with the impact of traffic shifts being largely underexplored. In this paper, we evaluate how the traffic from new apps (those unseen during training) and shifted apps (those affected by traffic changes) impacts classification performance by leveraging Meta Mimetic , a state-of-the-art multimodal FSL approach. Meta Mimetic exploits multiple views of traffic data and integrates an ad-hoc learning procedure to adapt to the evolving mobile-app traffic using minimal supervised data. Our experiments are conducted on two publicly available datasets, encompassing both new apps and shifted apps. First, we assess the presence of traffic changes in shifted apps through Markov-based statistical modeling and evaluate the impact on the performance of Meta Mimetic when considering such traffic. We then show that Meta Mimetic exhibits strong adaptability to shifts introduced by stricter encrypted protocols, having a performance degradation 2 × lower than single-modal baselines, as further validated using eXplainable AI (XAI) . Finally, in case of extreme data scarcity, we show that Meta Mimetic can effectively use old traffic for data augmentation, regardless of shifts, achieving up to a + 12 % F1-score improvement over alternative methods.
Davide Di Monda, Giampaolo Bovenzi, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Networks2
2026 A Federated and Incremental Network Intrusion Detection System for IoT Emerging Threats
abstract
Ensuring network security is increasingly challenging, especially in the Internet of Things (IoT) domain, where threats are diverse, rapidly evolving, and often device-specific. Hence, Network Intrusion Detection Systems (NIDSs) require(i)being trained on network traffic gathered in different collection points to cover the attack traffic heterogeneity,(ii)continuously learning emerging threats (viz., 0-day attacks), and(iii)be able to take attack countermeasures as soon as possible. In this work, we aim to improve Artificial Intelligence (AI)-based NIDS design & maintenance by integrating Federated Learning (FL) and Class Incremental Learning (CIL). Specifically, we devise a Federated Class Incremental Learning (FCIL) framework–suited for early-detection settings—that supports decentralized and continual model updates, investigating the non-trivial intersection of FL algorithms with state-of-the-art CIL techniques to enable scalable, privacy-preserving training in highly non-IID environments. We evaluate FCIL on three IoT datasets across different client scenarios to assess its ability to learn new threats and retain prior knowledge. The experiments assess potential key challenges in generalization and few-sample training, and compare NIDS performance to monolithic and centralized baselines.
Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.3
2025 Explainable federated class incremental learning for Encrypted Network Traffic classification
abstract
Network traffic has experienced substantial growth in recent years, requiring the implementation of more advanced techniques for effective management. In this context, Traffic Classification (TC) helps in successfully handling the network by identifying what is flowing through it. Nowadays, data-driven approaches—viz., Machine Learning (ML) and Deep Learning (DL)—are widely employed to address this task. However, these approaches struggle to keep pace with the ever-changing nature of traffic due to the introduction of new or updated services/apps and exhibit a decision-making process not interpretable. Furthermore, network traffic can vary significantly by geographic area , requiring a decentralized privacy-preserving approach to update classifiers collaboratively. In this work, we propose a Federated Class Incremental Learning (FCIL) framework that integrates Class Incremental Learning (CIL) and Federated Learning (FL) for network TC while incorporating a comprehensive eXplainable Artificial Intelligence (XAI) methodology, tackling the challenges of updating traffic classifiers, managing the geographic diversity of traffic along with data privacy, and interpreting the decision-making process, respectively. To assess our proposal, we leverage two publicly available encrypted network traffic datasets. Our findings uncover that, in small networks, fewer synchronizations facilitate retaining old knowledge, while larger networks reveal an approach-dependent pattern, yet still exhibiting good retention performance. Moreover, in both small and larger networks, frequent updates enhance the assimilation of new information . Notably, B i C + is the most effective approach in small networks (i.e., 2 clients) while i C a R L + performs best in larger networks (i.e., 10 clients), obtaining 82% and 79% F1 on C E S N E T - T L S 2 2 , respectively. Leveraging XAI techniques, we analyze the effect of incorporating a per-client bias correction layer. By integrating sample-based and attribution-based explanations, we provide detailed insights into the decision-making process of FCIL approaches .
Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Comput. Networks3
2025 Attack-adaptive network intrusion detection systems for IoT networks through class incremental learning
abstract
The advent of the Internet of Things (IoT) has ushered in an era of unprecedented connectivity and convenience, enabling everyday objects to gather and share data autonomously, revolutionizing industries, and improving quality of life. However, this interconnected landscape poses cybersecurity challenges, as the expanded attack surface exposes vulnerabilities ripe for exploitation by malicious actors. The surge in network attacks targeting IoT devices underscores the urgency for robust and evolving security measures. Class Incremental Learning (CIL) emerges as a dynamic strategy to address these challenges, empowering Machine Learning (ML) and Deep Learning (DL) models to adapt to evolving threats while maintaining proficiency in detecting known ones. In the context of IoT security, characterized by the constant emergence of novel attack types, CIL offers a powerful means to enhance Network Intrusion Detection Systems (NIDS) resilience and network security. This paper aims to investigate how CIL methods can support the evolution of NIDS within IoT networks ( i ) by evaluating both attack detection and classification tasks — optimizing hyperparameters associated with the incremental update or to the traffic input definition—and ( i i ) by addressing also key research questions related to real-world NIDS challenges —such as the explainability of decisions, the robustness to perturbation of traffic inputs, and scenarios with a scarcity of new-attack samples. Leveraging 4 recently-collected and comprehensive IoT attack datasets , the study aims to evaluate the effectiveness of CIL techniques in classifying 0-day attacks.
Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Comput. Networks2
2025 Adaptable, incremental, and explainable network intrusion detection systems for internet of things
Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Eng. Appl. Artif. Intell.2
2025 Mapping the Landscape of Generative AI in Network Monitoring and Management
abstract
Generative Artificial Intelligence (GenAI) models such as LLMs, GPTs, and Diffusion Models have recently gained widespread attention from both the research and the industrial communities. This survey explores their application in network monitoring and management, focusing on prominent use cases, as well as challenges and opportunities. We discuss how network traffic generation and classification, network intrusion detection, networked system log analysis, and network digital assistance can benefit from the use of GenAI models. Additionally, we provide an overview of the available GenAI models, datasets for large-scale training phases, and platforms for the development of such models. Finally, we discuss research directions that potentially mitigate the roadblocks to the adoption of GenAI for network monitoring and management. Our investigation aims to map the current landscape and pave the way for future research in leveraging GenAI for network monitoring and management.
Giampaolo Bovenzi, Francesco Cerasuolo, Domenico Ciuonzo, Davide Di Monda, Idio Guarino, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.1
2024 Explainable Few-Shot Class Incremental Learning for Mobile Network Traffic Classification
abstract
Mobile Traffic Classification (TC) increasingly relies on Machine Learning (ML) and Deep Learning (DL) to enhance network management. Yet, these methods face challenges in (i) classifying new apps, (ii) handling data scarcity from frequent app releases/updates, and (iii) explaining their decisions due to their opaqueness. Class Incremental Learning (CIL) and Few-Shot Learning (FSL) enable to quickly update models and learn with very limited data, respectively, while eXplainable AI (XAI) enhances decision transparency. In this work, we merge CIL and FSL to update models with new apps under few sample constraints. First, we introduce SWEET, a CIL-originated approach that flexibly accommodates different few-sample scenarios via adaptive traffic augmentation. Second, we devise an XAI methodology based on visualization-, sample-, and attribution-based techniques to explore practical incremental learning. We evaluate both contributions on the public mobile traffic dataset MIRAGE19.
Francesco Cerasuolo, Giampaolo Bovenzi, Vincenzo Spadari, Domenico Ciuonzo, Antonio Pescapè
GLOBECOM2
2024 An MLOps Framework for Explainable Network Intrusion Detection with MLflow
abstract
The surge in network traffic has required advanced techniques to ensure network security. Network Intrusion Detection Systems (NIDSs), which increasingly employ Machine Learning (ML) and Deep Learning (DL) methodologies, play a pivotal role in this task by continuously monitoring network traffic patterns and identifying suspicious activities. To address the complexities of developing ML- and DL-based NIDS, MLOps tools have been designed to optimize model deployment, monitoring, and management in production environments, streamlining model development. These tools enable efficient experimentation, version management, and logging of artifacts for network administrators and data scientists. In this work, we design a framework powered by MLflow to manage the ML pipeline from data handling to results visualization. To show the effectiveness of our framework, we conducted an experimental campaign on 4 broadly used security datasets (viz. NSL-KDD, IoT-23, Kitsune, and TON_IoT) performing crucial tasks for intrusion detection, namely anomaly detection, binary misuse detection, and multiclass misuse detection.
Vincenzo Spadari, Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè
ISCC3
2024 MEMENTO: A novel approach for class incremental learning of encrypted traffic
abstract
In the ever-changing digital environment, ensuring the ongoing effectiveness of traffic analysis and security measures is crucial. Therefore, Class Incremental Learning (CIL) in encrypted Traffic Classification (TC) is essential for adapting to evolving network behaviors and the rapid development of new applications. However, the application of CIL techniques in the TC domain is not straightforward, usually leading to unsatisfactory performance figures. Specifically, the improvement goal is to reduce forgetting on old apps and increase the capacity in learning new ones, in order to improve overall classification performance— reducing the drop from a model “trained-from-scratch”. The contribution of this work is the design of a novel fine-tuning approach called MEMENTO, which is obtained through the careful design of different building blocks: memory management, model training, and rectification strategies. In detail, we propose the application of traffic biflows augmentation strategies to better capitalize on old apps biflows, we introduce improvements in the distillation stage, and we design a general rectification strategy that includes several existing proposals. To assess our proposal, we leverage two publicly-available encrypted network traffic datasets, i.e., MIRAGE19 and CESNET-TLS22. As a result, on both datasets MEMENTO achieves a significant improvement in classifying new apps (w.r.t. the best-performing alternative, i.e., BiC) while maintaining stable performance on old ones. Equally important, MEMENTO achieves satisfactory overall TC performance, filling the gap toward a trained-from-scratch model and offering a considerable gain in terms of time (up to 10× speed-up) to obtain up-to-date and running classifiers. The experimental evaluation relies on a comprehensive performance evaluation workbench for CIL proposals, which is based on a wider set of metrics (as opposed to the existing literature in TC).
Francesco Cerasuolo, Alfredo Nascita, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
Comput. Networks3
2024 Classifying attack traffic in IoT environments via few-shot learning
abstract
The Internet of Things (IoT) is a key enabler for critical systems, but IoT devices are increasingly targeted by cyberattacks due to their diffusion and hardware and software limitations. This calls for designing and evaluating new effective approaches for protecting IoT systems at the network level. While recent proposals based on machine- and deep-learning provide effective solutions to the problem of attack-traffic classification, their adoption is severely challenged by the amount of labeled traffic they require to train the classification models. In fact, this results in the need for collecting and labeling large amounts of malicious traffic, which may be hindered by the nature of the malware possibly generating little and hard-to-capture network activity. To tackle this challenge, we adopt few-shot learning approaches for attack-traffic classification, with the objective to improve detection performance for attack classes with few labeled samples. We leverage advanced deep-learning architectures to perform feature extraction and provide an extensive empirical study—using recent and publicly available datasets—comparing the performance of an ample variety of solutions based on different learning paradigms, and exploring a number of design choices in depth (impact of embedding function, number of classes of attacks, or number of attack samples). In comparison to non-few-shot baselines, we achieve a relative improvement in the F1-score ranging from 8% to 27%.
Giampaolo Bovenzi, Davide Di Monda, Antonio Montieri, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.1
2024 Benchmarking Class Incremental Learning in Deep Learning Traffic Classification
abstract
Traffic Classification (TC) is experiencing a renewed interest, fostered by the growing popularity of Deep Learning (DL) approaches. In exchange for their proved effectiveness, DL models are characterized by a computationally-intensive training procedure that badly matches the fast-paced release of new (mobile) applications, resulting in significantly limited efficiency of model updates. To address this shortcoming, in this work we systematically explore Class Incremental Learning (CIL) techniques, aimed at adding new apps/services to pre-existing DL-based traffic classifiers without a full retraining, hence speeding up the model’s updates cycle. We investigate a large corpus of state-of-the-art CIL approaches for the DL-based TC task, and delve into their working principles to highlight relevant insight, aiming to understand if there is a case for CIL in TC. We evaluate and discuss their performance varying the number of incremental learning episodes, and the number of new apps added for each episode. Our evaluation is based on the publicly available$\mathtt {MIRAGE19}$dataset comprising traffic of 40 popular Android applications, fostering reproducibility. Despite our analysis reveals their infancy, CIL techniques are a promising research area on the roadmap towards automated DL-based traffic analysis systems.
Giampaolo Bovenzi, Alfredo Nascita, Lixuan Yang, Alessandro Finamore, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
IEEE Trans. Netw. Serv. Manag.1
2023 Adaptive Intrusion Detection Systems: Class Incremental Learning for IoT Emerging Threats
abstract
In the evolving landscape of Internet of Things (IoT) security, the need for continuous adaptation of defenses is critical. Class Incremental Learning (CIL) can provide a viable solution by enabling Machine Learning (ML) and Deep Learning (DL) models to $( i)$ learn and adapt to new attack types (0-day attacks), $( ii)$ retain their ability to detect known threats, (iii) safeguard computational efficiency (i.e. no full re-training). In IoT security, where novel attacks frequently emerge, CIL offers an effective tool to enhance Intrusion Detection Systems (IDS) and secure network environments. In this study, we explore how CIL approaches empower DL-based IDS in IoT networks, using the publicly-available IoT-23 dataset. Our evaluation focuses on two essential aspects of an IDS: $( a)$ attack classification and $( b)$ misuse detection. A thorough comparison against a fully-retrained IDS, namely starting from scratch, is carried out. Finally, we place emphasis on interpreting the predictions made by incremental IDS models through eXplainable AI (XAI) tools, offering insights into potential avenues for improvement.
Francesco Cerasuolo, Giampaolo Bovenzi, Christian Marescalco, Francesco Cirillo, Domenico Ciuonzo, Antonio Pescapè
IEEE Big Data2
2023 IoT Botnet-Traffic Classification Using Few-Shot Learning
abstract
The Internet of Things (IoT) is experiencing a constant expansion, embedding connectivity into everyday objects for increased efficiency. Despite this, security vulnerabilities pose a growing concern because IoT devices often lack robust security measures, leaving room for IoT botnet malware action and underlining the critical need for increased IoT security. During the last years, Machine Learning (ML) and Deep Learning (DL) have offered effective tools against IoT attacks, but these solutions struggle with identifying novel threats. In fact, the dynamic nature of IoT ecosystems requires data-driven systems capable of responding promptly to emerging threats, characterized by the limited availability of samples for training.In this context, we exploit Few-Shot Learning (FSL) to effectively identify emerging network attacks within the traffic generated by IoT devices by performing botnet-traffic classification. In detail, FSL enables ML and DL models to recognize and adapt to novel classes of attack traffic with minimal available samples, tackling class imbalance issues between high-frequency and lowfrequency attacks (which generate high and low network traffic, respectively). This strategic integration of FSL is crucial in enhancing overall IoT security, providing a proactive approach to handle dynamic and imbalanced scenarios, and ensuring the resilience of interconnected systems. The experimental evaluation is conducted on the publicly available IoT-23 dataset. The results highlight that the best FSL approach obtains the highest performance figures with just 3 shots, scoring 92% F1-score when discriminating low-frequency botnet malware. Noteworthy, satisfactory performance (up to 93% F1-score) is achieved also in misuse detection, proving the capability to distinguish between legitimate and malicious traffic.
Davide Di Monda, Giampaolo Bovenzi, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Big Data2
2023 Network anomaly detection methods in IoT environments via deep learning: A Fair comparison of performance and robustness
abstract
The Internet of Things (IoT) is a key enabler in closing the loop in Cyber-Physical Systems, providing “smartness” and thus additional value to each monitored/controlled physical asset. Unfortunately, these devices are more and more targeted by cyberattacks because of their diffusion and of the usually limited hardware and software resources. This calls for designing and evaluating new effective approaches for protecting IoT systems at the network level (Network Intrusion Detection Systems, NIDSs). These in turn are challenged by the heterogeneity of IoT devices and the growing volume of transmitted data. To tackle this challenge, we select a Deep Learning architecture to perform unsupervised early anomaly detection. With a data-driven approach, we explore in-depth multiple design choices and exploit the appealing structural properties of the selected architecture to enhance its performance. The experimental evaluation is performed on two recent and publicly available IoT datasets (IoT-23 and Kitsune). Finally, we adopt an adversarial approach to investigate the robustness of our solution in the presence of Label Flipping poisoning attacks. The experimental results highlight the improved performance of the proposed architecture, in comparison to both well-known baselines and previous proposals.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Secur.1
2022 Data Poisoning Attacks against Autoencoder-based Anomaly Detection Models: a Robustness Analysis
abstract
The Internet of Things (IoT) is experiencing a strong growth in both industrial and consumer scenarios. At the same time, the devices taking part in delivering IoT services—usually characterized by limited hardware and software resources—are more and more targeted by cyberattacks. This calls for designing and evaluating new approaches for protecting IoT systems, which are challenged by the limited computational capabilities of devices and by the scarce availability of reliable datasets. In line with this need, in this paper we compare three state-of-the-art machine-learning models used for Anomaly Detection based on autoencoders, i.e. shallow Autoencoder, Deep Autoencoder (DAE), and Ensemble of Autoencoders (viz. KitNET). In addition, we evaluate the robustness of such solutions when Data Poisoning Attack (DPA) occurs, to assess the detection performance when the benign traffic used for learning the legitimate behavior of devices is mixed to malicious traffic. The evaluation relies on the public Kitsune Network Attack Dataset. Results reveal that the models do not differ in performance when trained with unpoisoned benign traffic, reaching (at 1% FPR) an F1 score of ≈ 97%. However, when DPA occurs, DAE proves to be the more robust in detection, showing more than 50% of F1 Score with 10% poisoning. Instead, the other models show strong performance drops (down to ≈ 20% F1 Score) by injecting only 0.5% of the malicious traffic.
Giampaolo Bovenzi, Alessio Foggia, Salvatore Santella, Alessandro Testa, Valerio Persico, Antonio Pescapè
ICC1
2022 A Comparison of Machine and Deep Learning Models for Detection and Classification of Android Malware Traffic
abstract
With the increasing popularity of mobile-app services, malicious software is increasing as well. Accordingly, the interest of the scientific community in Machine and Deep Learning solutions for detecting and classifying malware traffic is growing. In this work, we provide a fair assessment of the performance of a number of data-driven strategies to detect and classify Android malware traffic. Three models are taken into account (Decision Tree, Random Forest, and 1-D Convolutional Neural Network) considering both flat (i.e. non-hierarchical) and hierarchical approaches. The experimental analysis performed using a state-of-art dataset (CIC-AAGM2017) reports that Random Forest exhibits the best performance in a flat setup, while moving to a hierarchical approach could cause significant variation in precision and recall. Such results push for further investigating advanced hierarchical setups and learning schemes.
Giampaolo Bovenzi, Francesco Cerasuolo, Antonio Montieri, Alfredo Nascita, Valerio Persico, Antonio Pescapè
ISCC1
2022 Hierarchical Classification of Android Malware Traffic
abstract
In the last few years, Android mobile devices have encountered a large spread and nowadays a huge part of the traffic traversing the Internet is related to them. In parallel, the number of possible threats and attacks has also increased, thus emphasizing the need for accurate automatic malware detection systems. In this paper, we design and evaluate a system to detect whether a traffic object (biflow) is benign or malicious, possibly understanding its specific nature in the latter case. The proposal leverages machine learning in a hierarchical fashion, in order to capitalize on the structure of the traffic data and reap both design and performance benefits. The comparative evaluation—performed considering the public CICAndMal2017 dataset—assesses the performance of several machine-learning algorithms and witnesses that the hierarchical approach leads to improved performance w.r.t. the flat approach (up to +0.18 F1-score, depending on the granularity of the analysis and the machine learning algorithm considered). In addition, we evaluate the impact of a reject-option mechanism, showing the trade-off between classification accuracy and ratio of classified biflows.
Giampaolo Bovenzi, Valerio Persico, Antonio Pescapè, Anna Piscitelli, Vincenzo Spadari
TrustCom1
2021 Packet-level prediction of mobile-app traffic using multitask Deep Learning
Antonio Montieri, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Comput. Networks2
2021 Characterization and Prediction of Mobile-App Traffic Using Markov Modeling
abstract
Modeling network traffic is an endeavor actively carried on since early digital communications, supporting a number of practical applications, that range from network planning and provisioning to security. Accordingly, many theoretical and empirical approaches have been proposed in this long-standing research, most notably, Machine Learning (ML) ones. Indeed, recent interest from network equipment vendors is sparking around the evaluation of solid information-theoretical modeling approaches complementary to ML ones, especially applied to new network traffic profiles stemming from the massive diffusion of mobile apps. To cater to these needs, we analyze mobile-app traffic available in the public dataset MIRAGE-2019 adopting two related modeling approaches based on the well-known methodological toolset of Markov models (namely, Markov Chains and Hidden Markov Models). We propose a novel heuristic to reconstruct application-layer messages in the common case of encrypted traffic. We discuss and experimentally evaluate the suitability of the provided modeling approaches for different tasks: characterization of network traffic (at different granularities, such as application, application category, and application version), and prediction of network traffic at both packet and message level. We also compare the results with several ML approaches, showing performance comparable to a state-of-the-art ML predictor (Random Forest Regressor). Also, with this work we provide a viable and theoretically sound traffic-analysis toolset to help improving ML evaluation (and possibly its design), and a sensible and interpretable baseline.
Giuseppe Aceto, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.2
2020 A Hierarchical Hybrid Intrusion Detection Approach in IoT Scenarios
abstract
Internet of Things (IoT) fosters unprecedented network heterogeneity and dynamicity, thus increasing the variety and the amount of related vulnerabilities. Hence, traditional security approaches fall short, also in terms of resulting scalability and privacy. In this paper we propose H2ID, a two-stage hierarchical Network Intrusion Detection approach. H2ID performs (i) anomaly detection via a novel lightweight solution based on a MultiModal Deep AutoEncoder (M2-DAE), and (ii) attack classification, using soft-output classifiers. We validate our proposal using the recently-released Bot-IoT dataset, inferring among four relevant categories of attack (DDoS, DoS, Scan, and Theft) and unknown attacks. Results show gains of the proposed M2-DAE in the case of simple anomaly detection (up to -40% false-positive rate when compared with several baselines at same true positive rate) and for H2ID as a whole when compared to the best-performing misuse detector approach (up to ≈ +5% F1 score). Besides the performance advantages, our system is suitable for distributed and privacy-preserving deployments while limiting re-training necessities, in line with the high efficiency as well as the flexibility required in IoT scenarios.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
GLOBECOM1