Share

Export Citation

APA
MLA
Chicago
Harvard
Vancouver
BIBTEX
RIS
Universitas Hasanuddin
Research output:Contribution to journalArticlepeer-review

Enhancing Network Intrusion Detection for TLS Traffic Using Deep Learning

Muttaqien H.

Engineering Technology and Applied Science Research

Q2
Published: 2025

Abstract

The increased utilization of Transport Layer Security (TLS) encryption in contemporary network communication introduces new obstacles for Network Intrusion Detection Systems (NIDS), since encrypted traffic constrains the efficacy of traditional signature-based techniques. This study presents a real-time intrusion detection method for TLS traffic utilizing a combination of Convolutional Neural Networks (CNNs) and Bidirectional Long Short-Term Memory (BiLSTM) networks. CNNs are employed to derive spatial representations of TLS information from Suricata logs, including JA3 fingerprints, cipher suites, and connection statistics, and BiLSTM is utilized to capture bidirectional temporal dependencies of encrypted traffic to identify intricate anomaly patterns. This model was evaluated utilizing an extensive TLS dataset comprising both valid and malicious traffic, including Command-and-Control (C2) connections, malware communication, and data exfiltration. The experimental findings indicate that the CNN–BiLSTM model attained a detection accuracy of 98.7%, a False Positive Rate (FPR) of 1.4%, and an average processing time of 12.9 ms per session, rendering it appropriate for real-time application in corporate network security systems. This methodology enhances the capability of hybrid Deep Learning (DL) models to identify concealed dangers in TLS communication without requiring data decryption.

Access to Document

10.48084/etasr.13267

Other files and links

Fingerprint

Computer scienceSciences
EncryptionSciences
Deep learningSciences
Intrusion detection systemSciences
Artificial intelligenceSciences
Data miningSciences
Convolutional neural networkSciences
Rendering (computer graphics)Sciences
Network securitySciences
Anomaly detectionSciences
Traffic classificationSciences
Artificial neural networkSciences
Machine learningSciences
MalwareSciences
Transport Layer SecuritySciences
CipherSciences
Traffic analysisSciences
Real-time computingSciences
Information securitySciences
Computer networkSciences
Data securitySciences
SQLSciences
Layer (electronics)Sciences
Pattern recognition (psychology)Sciences