Network Forensics using Deep Q-Networks and Explainable Artificial Intelligence
Meghana Solanki, Sangita Santosh Chaudhari · 2024
The increasing complexity and frequency of Distributed Denial-of-Service (DDoS) attacks demand sophisticated and effective network forensics methodologies. Utilizing Deep Q Networks (DQN) and Explainable Artificial Intelligence (XAI) techniques such as Local Interpretable Model-Agnostic Explanations (LIME) and DeepSHAP (SHapley Additive exPlanations), our approach initiates with the collection of extensive data from various network endpoints. Employing k-Means Clustering for data preprocessing enhances dataset quality, a critical factor for accurate pattern detection and reducing redundancy. Transforming data into multiple representations extracts essential features, exposing hidden events that signal DDoS attacks. Our core approach involves network forensics analysis using a sophisticated DQN Classifier capable of identifying and analyzing intricate DDoS attack patterns, significantly reducing false positives and adapting to new attack vectors. Integration of LIME and DeepSHAP for XAI enhances interpretability, facilitating comprehension of the model’s decisions and fostering trust. By employing this methodology, organizations can substantially improve the accuracy and effectiveness of their network forensics efforts, maintain compliance with relevant regulations, and adapt to the ever-changing DDoS attack patterns that characterize the dynamic cybersecurity landscape.