Privacy-Aware Traffic Log Anonymization Method for Realizing Both Malicious Activity Detection and Privacy

Takeshi Ogawa, Hajime Shimada, Hirokazu Hasegawa, Yukiko Yamaguchi · 2025

The number of cyber-attacks is still increasing, and a Network-based Intrusion Detection System (NIDS) plays an important role in countermeasures for the cyber-attacks. However, due to increases in both cyber-attacks and traffic amount, burden of supervisors who check NIDS logs also increases. To alleviate this burden, we propose a method for detecting malicious activity under anonymized traffic logs that can be reviewed by low-privilege staffs. By performing preliminary screening with these anonymized traffic logs, we can reduce the burdens of supervisors. To realize this concept, we propose a privacy-aware traffic log anonymization method. We defined privacy-sensitive features within the traffic logs and explored the importance of Gain metric analysis on LightGBM. Then, we applied simple anonymization to features that have not so large value in metrics and applied complex anonymization such as fine-grained quantization to preserve Gain of the key features. We evaluated the performance of malicious activity detection and found that it achieves over 96% performance in widely accepted metrics. Additionally, we assessed the anonymization performance and confirmed that the number of unique sessions was reduced to less than 1/10 after anonymization. Furthermore, we confirmed that the uniqueness metric after anonymization is usable as a feature in the classifier. It improves widely accepted classification performance metrics by 0.59 to 1.27 percentage points.

Read the paper · More papers on PaperTik