[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123664-en":3,"doc-seo-123664-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123664,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","Towards a Near-real-time Protocol Tunneling Detector based on Machine Learning Techniques","Cybersecurity attacks are accelerating rapidly in volume, sophistication, and cost, affecting both organizations and critical infrastructures. Expanded network perimeters during the COVID-19 period increased exploitable attack surface via malware and phishing, making continuous monitoring of network events essential. A near real-time protocol tunneling detector prototype inspects unencrypted network flows, extracts traffic features, and combines machine learning and deep learning to identify tunneling attacks, anomalies, and malicious patterns. The prototype is evaluated on benign and malicious datasets, achieving 97.1% overall accuracy and an F1-score of 95.6%.","Article  \nTowards a Near-real-time Protocol Tunneling Detector based on Machine Learning Techniques  \nFilippo Sobrero 1, Beatrice Clavarezza 1, Daniele Ucci 1, and Federica Bisio 1  \nCitation: Sobrero, F.; Clavarezza, B.; Ucci, D.; Bisio, F. Towards a  \nNear-real-time Protocol Tunneling Detector based on Machine Learning Techniques. J. Cybersecur. Priv. 2023, 1, 1–12. [https://doi.org/](https://doi.org/)  \nReceived:  \nRevised:  \nAccepted:  \nPublished:  \nCopyright: © 2023 by the authors. Submitted to J. Cybersecur. Priv. for possible open access publication under the terms and conditions of the Creative Commons Attribution (CC BY) license ([https://](https://)[ ](https://)[creativecommons.org/licenses/by/](creativecommons.org/licenses/by/)[ ](creativecommons.org/licenses/by/)[4.0/](4.0/)) .  \narXiv :2309 . 12720v1 [ cs .CR] 22 Sep 2023  \n1 aizoOn Technology Consulting; [name.surname@aizoongroup.com](name.surname@aizoongroup.com)  \n† This paper is an extended version of our paper published in IEEE Symposium Series on Computational Intelligence, 2021 .  \nAbstract: In the very last years, cybersecurity attacks have increased at an unprecedented pace, becoming ever more sophisticated and costly. Their impact has involved both private/public companies and critical infrastructures. At the same time, due to the COVID-19 pandemic, the security perimeters of many organizations expanded, causing an increase of the attack surface exploitable by threat actors through malware and phishing attacks. Given these factors, it is of primary importance to monitor the security perimeter and the events occurring in the monitored network, according toa tested security strategy of detection and response. In this paper, we present a protocol tunneling detector prototype which inspects, in near real time, a company’s network traffic using machine learning techniques. Indeed, tunneling attacks allow malicious actors to maximize the time in which their activity remains undetected. The detector monitors unencrypted network flows and extracts features to detect possible occurring attacks and anomalies, by combining machine learning and deep learning. The proposed module can be embedded in any network security monitoring platform able to provide network flow information along with its metadata. The detection capabilities of the implemented prototype have been tested both on benign and malicious datasets. Results show 97.1% overall accuracy and an F1-score equals to 95.6% .  \nKeywords: passive network analysis; dns tunneling; anomaly detection; machine learning; deep learning  \n1. Introduction  \nCybersecurity attacks keep increasing year over year at an unprecedented pace, becoming ever more sophisticated and costly [1,2] . The growth between 2021 and 2022 has resulted in a rise of attacks’ volume and impact on both private/public companies and critical infrastructures. Companies comprise digital service providers, public administrationsand governments, and include businesses operating in finance and health sectors. In particular, service providers have experimented more than 15% raise in intrusions (infamous has been the case of Solarwinds [3]) compared to 2021 [1], a trend destined to grow in the next years [4] . At the same time, due to the COVID-19 pandemic, the security perimeters of many organizations expanded to cope with the new needs of remote working, causing an increase of the attack surface exploitable by attackers [4] . The European Union Agency for Cybersecurity estimates that more than 10 terabytes of data are stolen monthly from target assets that are made unavailable, until a ransom is payed [1], while IBM calculates that the average cost of these attacks is $4.54M, arriving up to $5.12M [2] . On the other hand, malware attacks are still on the rise after the pause recorded during the pandemic and phishing continues to be the common attack vector for initial access [1] .  \nGiven these factors, it is of primary importance to monitor the securi","cbCaigvmmBwVbVnK","https://ap.wps.com/l/cbCaigvmmBwVbVnK","pdf",672658,1,12,"English","en",105,"# Introduction\n## Problem context and motivation\n## Near real-time protocol tunneling detection approach","[{\"question\":\"What security problem does the proposed detector address?\",\"answer\":\"It addresses tunneling attacks that encapsulate malicious communication inside legitimate protocols, allowing activity to remain undetected for longer.\"},{\"question\":\"How does the detector operate in terms of traffic visibility and timing?\",\"answer\":\"It inspects network traffic in near real time and focuses on unencrypted (cleartext) protocols, extracting features from network flows for detection.\"},{\"question\":\"What machine learning methods are used and how effective is the prototype?\",\"answer\":\"The detector combines machine learning and deep learning. Tested results on benign and malicious datasets report 97.1% overall accuracy and an F1-score of 95.6%.\"}]","Towards a Near-real-time Protocol Tunneling Detector based on Machine Learning Techniques | PDF",1785817910,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"towards-a-near-real-time-protocol-tunneling-detector-based-on-machine-learning-techniques","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/towards-a-near-real-time-protocol-tunneling-detector-based-on-machine-learning-techniques/123664/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security problem does the proposed detector address?","Question",{"text":75,"@type":76},"It addresses tunneling attacks that encapsulate malicious communication inside legitimate protocols, allowing activity to remain undetected for longer.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the detector operate in terms of traffic visibility and timing?",{"text":80,"@type":76},"It inspects network traffic in near real time and focuses on unencrypted (cleartext) protocols, extracting features from network flows for detection.",{"name":82,"@type":73,"acceptedAnswer":83},"What machine learning methods are used and how effective is the prototype?",{"text":84,"@type":76},"The detector combines machine learning and deep learning. Tested results on benign and malicious datasets report 97.1% overall accuracy and an F1-score of 95.6%.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]