Bloom Filter Traffic Encoding for Multi-Model Intrusion Detection and Attack Quantification
Ana Carolina R. Mendes, Thi Mai Trang Nguyen, Diogo M. F. Mattos · 2025
The increasing volume of network traffic and the growing sophistication of cyber-attacks pose challenges for the scalability and accuracy of Intrusion Detection Systems (IDS). A specific limitation is the difficulty of detecting intrusions and estimating the intensity of attacks in resource-constrained environments, such as access networks with IoT devices. This article proposes a modular framework that encodes network flows into fixed-size Bloom Filter matrices, enabling scalable and efficient learning through different modeling strategies. The methodology was validated using real traffic collected from a Brazilian broadband network, and three approaches were tested: a baseline linear predictor, an ensemble based on XGBoost, and a Convolutional Neural Network (CNN). The linear model showed limited performance, with an R-squared of 0.0233, while the ensemble improved results, reaching an F1-score of 0.9790 and an R-squared of 0.3897. CNN achieved the highest overall performance, with near-perfect classification metrics, including an accuracy of 0.9965 and an F1-score of 0.9972, as well as a strong regression accuracy with an R-squared of 0.8260 and a mean absolute error of 0.0789. These findings confirm the effectiveness of Bloom-Filter-based summarization for lowlatency intrusion detection.