polito.it
Politecnico di Torino (logo)

AI for Intrusion Detection: Clustering Unknown Traffic and Payload Analysis

Mahdi Naderibeni

AI for Intrusion Detection: Clustering Unknown Traffic and Payload Analysis.

Rel. Luca Vassio. Politecnico di Torino, NON SPECIFICATO, 2025

[img] PDF (Tesi_di_laurea) - Tesi
Accesso riservato a: Solo utenti staff fino al 24 Aprile 2027 (data di embargo).
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (5MB)
Abstract:

Given the growing complexity of cyber threats, Intrusion Detection Systems (IDS) must advance to detect both established and novel attack vectors in real time. This study investigates the application of Artificial Intelligence (AI) methodologies in the context of intrusion detection, with a particular emphasis on two pivotal domains: payload analysis and the clustering of anomalous, previously unclassified network traffic. For payload classification, a novel deep learning framework is proposed, wherein raw hexadecimal payload data are converted into spectrogram representations. This transformation facilitates the deployment of a hybrid architecture combining Convolutional Neural Networks (CNN) with Long Short-Term Memory (LSTM) networks, thereby enabling the extraction of both spatial and temporal features. In addressing the challenge of unknown attack detection, this work introduces the Adaptive Clustering and Embedding Network (ACENet), a dual-phase model that concurrently learns compact latent feature representations and performs clustering within the embedding space to identify patterns indicative of malicious behavior. Empirical evaluations utilizing the CIC-IDS2017 and UNSW-NB15 benchmark datasets reveal that the proposed models not only improve classification performance but also demonstrate a robust capacity for zero-day attack detection through unsupervised learning. Collectively, these advancements contribute toward the development of more adaptive and intelligent IDS architectures capable of responding to the evolving landscape of network security threats.

Relatori: Luca Vassio
Anno accademico: 2025/26
Tipo di pubblicazione: Elettronica
Numero di pagine: 72
Soggetti:
Corso di laurea: NON SPECIFICATO
Classe di laurea: Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA
Ente in cotutela: Nokia Bell Labs (FRANCIA)
Aziende collaboratrici: Nokia Bell Labs France
URI: http://webthesis.biblio.polito.it/id/eprint/37900
Modifica (riservato agli operatori) Modifica (riservato agli operatori)