
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Vaishnavi V, Santhosh Devappa Dubari, Uzma Samreen
Madeena
Vaishnavi V, Department of CSE, East Point College of Engineering and Technology, Bengaluru, Karnataka, India
Santhosh Devappa Dubari, Department of CSE, East Point College of Engineering and Technology, Bengaluru, Karnataka, India
Uzma Samreen Madeena, Department of CSE East Point College of Engineering and Technology, Bengaluru, Karnataka, India ***
Abstract - This paper presents an AI-based cyber threat detection system that analyses encrypted network traffic without the need for decryption. As most modern communication is now encrypted, traditional security systems that rely on payload inspection struggle to identify threats hidden within secure channels. Decrypting traffic introduces computational overhead and privacy risks, making it unsuitable for privacy-focused environments. To overcome this challenge, the proposed system examines traffic metadata such as packet size, flow duration, timing intervals, packet rate, and behavioural patterns instead of inspecting packet contents. A Random Forest machine learning modeltrained ontheCICIDSdatasetisemployedto classify network flows as normal or malicious, including threats such as DoS, DDoS, Port Scan, Probe, and Brute Force attacks. Live network traffic is captured using Scapy, and the extracted metadata is processed in real time to generate predictions. When abnormal activity is detected, the system immediately triggers alerts and updates an interactive web dashboard developed using Flask and SocketIO, providing visual insights into traffic behaviour, threat severity, and alert logs. Experimental evaluation demonstrates that the proposed approach achieves a detection accuracy of 95%, outperforming alternative classifiers such as Naive Bayes (86%), KNN (88%), SVM (91%), and Decision Tree (89%). Performance is assessed using standard metricsIncludingaccuracy,precision,recall, F1-score, and detection latency, confirming the system’s suitability for real-time deployment in encrypted network environments. By combining AI-driven analysis with realtime visualizationandautomatedalerting, this work offers a lightweight, efficient, and privacy-preserving solution for modern cybersecurity requirements.
Key Words: Privacy Preserving Detection, Encrypted Traffic Analysis, No Decryption Approach, Metadata Based Classification, Machine Learning, Random Forest, Cyber Threat Detection, Real Time Monitoring.
Modern network communication relies heavily on encryptiontoprotectuserdata,butthiscreatesachallenge for traditional security systems that depend on inspecting packet content to identify threats. Since encrypted traffic hidesthepayload,techniquessuchasdeeppacketinspection becomeineffective,anddecryptingdataintroducesprivacy risksandhighprocessingoverhead.Asattackersincreasingly exploit encrypted channels, there is a growing need for security solutions that can detect malicious activity withoutaccessingsensitiveinformation.
Apromisingapproachistoanalyzetrafficmetadata,such as packet size, flow duration, timing intervals, and packet rate, which reveal behavioral patterns even when the contentisencrypted.With thehelpofmachine learning, thesepatternscanbestudiedtoclassifynetworkflowsas normal or suspicious. Real time dashboards further support monitoring by presenting alerts and traffic insightsinavisualandeasytounderstandformat.
Basedonthisidea,theproposedsystemusesAItodetect cyber threats in encrypted traffic without performing decryption. By combining metadata analysis, a trained RandomForestmodel,livepacketcapture,anddashboard visualization,thesystemprovidesanefficientandprivacy preservingsolutionsuitableformodernsecurenetworks.
Today’s digital world depends heavily on online communication,andmostofthiscommunicationisprotected throughencryptiontokeepuserinformationprivate.While encryption is essential, it creates a major challenge for organizations that need to monitor their networks for harmfulactivities.Whendataishiddeninsideencrypted traffic,itbecomesdifficulttounderstandwhethertheactivity is normal or potentially dangerous. This problem exists becausesecurityteamscannolongerseewhatisinsidethe databeingtransmitted,yetattacksstillhappenthroughthe sameencryptedchannels.Asaresult,users,companies,and

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
onlineservices areall affected, sincethreats can spread withoutbeingeasilynoticed.Withcyberattacksincreasing everyyearandmoreservicesmovingonline,theneedto identifysuspiciousbehaviorinencryptedcommunicationhas becomemoreimportantthanever.Areliablewaytodetect harmful activity without violatinguser privacyis now a criticalrequirementformodernnetworksecurity.
Modern network traffic is heavily encrypted, making traditional security systems unable to inspect data and detect hidden threats. Existing methods that rely on reading packet contentfail underencryptionand create privacyconcerns.As attackersexploitthisgap, thereisa growing need for a new approach that can identify suspicious activity in encrypted traffic without breaking userprivacy.
Todesignanddevelopasystemthatcandetectcyber threats hidden within encrypted network traffic without performing any form of decryption, by focusing entirely on metadata such as packet size, timing behavior, and flow characteristics, allowing thesystemtoidentifyabnormaltrafficpatternswith measurableaccuracywhilemaintaininguserprivacy.
To classify network activity into normal and suspicious categories in real time, enabling the detectionofmajorcyberattackssuchasDoS,DDoS,Port Scanning, and Brute Force attempts, and ensuring that harmful behavior is recognized at the earliest possiblestagefortimelyintervention.
To build an automated and intelligent web based dashboardthatprovidesclearvisualizationofalerts, live traffic summaries, and monitoring results, helping users interpret network behavior quickly, improving situational awareness, and supporting fasterandmoreinformedsecuritydecisions.
To improve the overall speed, reliability, and efficiencyofthreatdetectionbyminimizingmanual effort and avoiding heavy data processing, ensuring thatthesystemfunctionsasalightweight,scalable, andprivacypreservingsolutionsuitableformodern encryptednetworkenvironments.
The system is designed to be used in environments where encrypted network communication is common, includingeducationalinstitutions,corporatenetworks,data centers,andinternetserviceplatforms.Itcanbe used by network administrators, cybersecurity teams, and organizationsseekingprivacypreservingthreatdetection. The system monitors real time traffic behavior, helping usersidentifyunusualactivitywithoutexposingsensitive data. While it focuses on major threats such as DoS and PortScanning,futureversionsmayexpandtohandlemore complex attack types and larger network scales. The system can also be integrated into existing security workflowstoimprovevisibilityinencryptedenvironments. Its real world usability lies in offering a lightweight, automated, and privacy focused approach to threat monitoringthatadaptstomodernsecurityneeds.
1. AI Driven Encrypted Traffic Threat Detection–2024
Researchers inthisstudyexplorehowcyberattacks can be identifiedwithinSSLandTLSencryptedcommunication without accessing the actual payload.Theirworkshows that machine learning models can recognize unusual behavior by examining metadata trends such as timing, flowduration,andpacketsize.Thefindingssuggeststrong potential for privacy friendly threat detection. However, thestudyfocusesmainlyonexperimentalresultsanddoes not address real time deployment or integration with monitoringtools.
Thisworkinvestigatestheuseofflowlevelcharacteristics to detect malicious traffic while completely avoiding packet content inspection. Techniques such as gradient boosted models and deep learning are used to classify encryptedflowsmoreaccuratelythantraditionalsystems. Althoughtheapproachprotectsuserprivacy,itismostly tested offline and does not include a simple mechanism for live alerting or operational use in practical environments.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
This work proposes a multi-phase encrypted traffic classification framework that extracts behavioural and temporalmetadatafeaturesfromnetworkflowswithout decryptingpacketpayloads.Byanalysingtrafficpatterns at different phases of a session, the approach improves detection accuracy compared to traditional single-stage methods. Althoughthe frameworkdemonstrates strong classification performance on benchmark datasets, it primarily focuses on offline analysis and does not integratereal-timevisualizationdashboardsorautomated mitigation mechanisms, which limits its applicability in operationalsecurityenvironments.
Thisstudyhighlightshowvisualizationtoolscansupport cybersecurity analysts by presenting alerts, summaries, and AI generated insights in real time. Dashboards help usersquicklyunderstandongoingnetworkbehaviorand respond to threats faster. Even so, most existing dashboards remain separate from encrypted traffic detectionenginesanddonotprovideaunifiedendtoend system.
Thissurveyreviewsmachine-learningtechniquesfor analysing encrypted traffic using payload-independent features such as packet size, flow statistics, timing intervals,andtrafficdirection.Theauthorsemphasizethat ensemblemodels,includingRandomForest,oftenachieve a strong balance between accuracy and computational efficiency for practical deployments. The study also discusses challenges related to real-time deployment, false-positive reduction, and system integration, highlighting the need for unified solutions that combine detection, visualization, and automated response objectivesaddressedbytheproposedsysteminthiswork.
Traditionalcyberthreatdetectiontechniquesprimarilyrely on examining the actual content of networkpacketsto identifymaliciouspatterns.Themostwidelyusedapproachis signature based detection, where the system compares incoming traffic with a database of known attack signatures.Whileeffectiveforfamiliarthreats,itstruggles
withneworevolvingattacksthatdo not match existing patterns. Another common method is deep packet inspection,whichscanspacketpayloadstodetectharmful behavior. However, thistechnique becomes ineffective when traffic is encrypted,sincethesystemcannotview thehiddencontent.
Some tools use rule based detection, where analysts manually create rules for suspicious behavior, but these systemsrequireconstantupdatesandexpertinvolvement. Anomalybaseddetectionattemptstoflagunusualpatterns, yet it often produces false alarms and may misinterpret legitimatetrafficasdangerous.Asencryptionbecomesthe defaultacrossnetworks,thesetraditional techniques face increasinglimitations,makingitdifficultfororganizationsto monitor threats without compromising user privacy or systemperformance.
Traditionalnetworkmonitoringsystemsdependheavily on inspecting packet content to identify threats, which becomes ineffective when traffic is encrypted. These systemscannotaccesshiddenpayloads,leaving alargeblind spotthatattackersoftenexploit.Theyalsorequirefrequent rule updates and manual tuning, making them slow to adapttoneworunknownattacks.Deeppacketinspection introduces privacy concerns and increases processing overhead, which limits real time performance. Many traditional tools detect threats only after an attack has alreadyoccurred,reducingtheirusefulnessinfastmoving network environments. As encryption becomes more widespread, these limitations prevent conventional monitoringsystemsfromprovidingaccurate,reliable,and privacyconsciousprotection.
Although several studies explore detecting threats in encryptedtrafficusingmetadataandmachinelearning,most existingapproachesarelimitedtoofflineexperimentsand do not provide real time monitoring capabilities. Many systemslackanintegrateddashboardforvisualizingalerts or supporting quick decision making, which reduces their practical usability. Current techniquesalsorelyoncomplexorcomputationallyheavy models that are difficult to deploy in lightweight environments.Additionally,veryfewsolutionsofferendto end automation, where traffic is captured, analyzed, classified,andalertedwithoutmanualintervention.There remainsacleargapforaprivacypreserving,realtime,easy todeploysystemthatcanaccuratelydetectthreatsinside

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
The system uses a real-time processing pipeline where encryptednetworktrafficiscapturedandtransformedinto metadataforanalysis.Relevantfeaturesareextractedandfed intoa machinelearningmodel thatclassifieseachnetwork flow as normal or suspicious. Based on this decision, the systemeitherlogstheactivityorraisesalerts.Thesealertsare visualized on a web dashboard for continuous monitoring. Thisapproachpreservesuserprivacywhileenablingfastand accuratethreatdetection.

4.1
The systemusestwoprimarysourcesofdatatosupport both model training and real time detection. For offline training,theCICIDSdatasetisused,whichprovidesalarge collection of labeled network flows containing normal traffic and various cyberattacks suchasDoS,DDoS,Port Scan,andBrute Force.Thisdatasetoffersrichmetadata featuresthathelpthemodellearnbehavioraldifferences between legitimate and malicious traffic. For real time operation,livenetworkpacketsarecaptureddirectlyfrom thesystem’s network interface. These captured packets contain encrypted traffic, and only metadata such as
packetsize,timestamps,andflowdirectionisextracted.By combiningabenchmarkdatasetformodellearningwith live traffic for monitoring, the system ensures both accurate classification and practical deployment in real worldenvironments.
Datapreprocessingisperformedtoconvertrawnetwork traffic into a clean and structured format suitable for machine learning analysis. The encrypted packets capturedfromthenetworkcontainonlymetadata,sothe systemorganizesthisinformationintoflow-basedrecords by grouping packets that share the same source, destination,andprotocol.Missingorinconsistent values arehandled,andnumericalfieldssuchaspacketsize,interarrival time, and flow duration are standardized to maintain uniformity. The metadata is then transformed into feature vectors that align with the structure used duringmodeltraining.Thisstepensuresthatbothtraining datafromtheCICIDSdatasetandlivetrafficfollowthesame format, allowing the classifier to make accurate predictions. Proper preprocessing improves model performance,reducesnoise,andensuresreliablerealtime detection
Feature extraction focuses on converting raw encrypted trafficintomeaningfulbehavioralindicatorsthatcanbe analyzedbythemachinelearningmodel.Sincethepayload cannotbeinspected,thesystemextractsonlymetadatafrom each packet, including packet size, timestamp, flow direction, and protocol information. These packet-level detailsarethenaggregatedintoflow-basedfeaturessuch astotalpackets,averagepacketsize,flowduration,packet rate, and inter-arrival time statistics. These features capturehowadevicebehavesonthenetworkratherthan whatdataittransmits,makingthemsuitableforprivacypreserving analysis. The extracted features are aligned withthestructureusedintheCICIDSdatasettomaintain consistency during training and detection. This step ensuresthemodelreceivesaccurateandstandardizedinput thatreflectsreal-worldtrafficbehavior,enablingeffective separationofnormalandsuspiciousnetworkflows.
The machine learning component forms the core of the system’s threat detection capability. A Random Forest classifier is selectedduetoitsstability,highaccuracy,and abilityto handle complex network behavior patterns. The modelistrainedusingtheCICIDSdataset,whichcontains

2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
labeled examples of both normal traffic and various cyberattacks. During training, the model learns to distinguish malicious flows by recognizing unique patternsinmetadata-basedfeaturessuchaspacketrates, flowdurations,andsizevariations.Oncetrained,themodelis deployed in real time to evaluate incoming traffic. Each processed feature vector from live flows is fed into the classifier, which predicts whether the flow represents normal activity or a potential threat. This approach enables fast, automated decision-making without inspectingpacketcontent,makingthesystemeffectiveeven whentrafficisfullyencrypted.
After the machine learning model evaluates a flow, the system classifies the activity as either normal or suspicious based on the predicted threat level. This classification is performed in real time, allowing the system to identify attacks such as DoS, DDoS, Port Scanning,Probeattempts,orBruteForceactivityassoon asabnormalbehaviorisdetected.Onceaflowislabelledas malicious,thealertsystemisautomaticallytriggered.The systemgeneratesaninstantwarningmessageandsendsit totheuserthroughintegratednotificationchannels,such as a web dashboard or messaging service. At the same time,thedashboardupdatestodisplaythedetectedthreat, its source, and the associated confidence score. The alert system may also initiate automated actions, such as temporarilyblockingthesuspiciousIPaddresstoprevent further damage. This combined classification and alert mechanism ensures fast, accurate detection and immediateresponse,supportingcontinuousmonitoringin encryptednetworkenvironments.
The proposed system incorporates an automated IP blocking mechanism that provides immediate mitigation againstdetectedcyberthreatsinrealtime.Afteranetwork flow is classified by the machine learning model, the associated prediction confidence is evaluated against a predefined threat threshold, and flows identified as malicioustriggeranautomaticcontainmentresponse.The sourceIPaddressisdynamicallyblockedthroughfirewall rule enforcement, preventing subsequent packets from reachingprotectedservices.Tominimizefalseblockingand operationaldisruption,themechanismincludessafeguard checkssuchasallow-listedtrustedaddressesandexclusion ofprivatenetworkranges.Allblockingactionsarerecorded with timestamps, predicted attack categories, and confidencescoresforauditingandforensicanalysis,while the integrated dashboard visualizes these responses
instantaneously.Thisautomatedandcontrolledresponse framework significantly reduces reaction time to active attacksandstrengthensoverallnetworksecurityposture.

Pseudo-code:
BEGIN
Captureincomingnetworkpacket Extractpacketandflowfeatures Send featurestotrainedMLmodel
Receivepredicted labelandprobability
IFpredicted label="Malicious"ORprobability≥ Threshold THEN
IFsource ipNOTINAllowlistANDsource ipISNOT Private IP THEN
IFsource ipNOTINRecently Blocked ListTHEN Generate firewallruletoblocksource ip
Storesource ip,timestamp,andreasonindatabase Add source iptoRecently Blocked List ENDIF ENDIF ENDIF
Update dashboard with alert details
Continuemonitoringnetworktraffic END

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072

Tojustifytheselectionofanappropriatemachinelearning modelforintrusiondetection,acomparativeanalysiswas conductedamongmultipleclassificationalgorithms.The performanceofNaiveBayes,K-NearestNeighbors(KNN), SupportVectorMachine(SVM),DecisionTree,andRandom Forestwasevaluatedbasedondetectionaccuracyusingthe same dataset and feature set. This comparison helps in identifying the most effective algorithm for real-time intrusiondetectionandprevention.

Algorithms
Fig. 6,1 presents the accuracy comparison of various machinelearningalgorithmsusedforintrusiondetection. Amongtheevaluatedmodels,theRandomForestclassifier achieves the highest detection accuracy of 95%, outperformingNaiveBayes,KNN,SVM,andDecisionTree algorithms.TheimprovedperformanceofRandomForest canbeattributedtoitsensemblelearningapproach,which combinesmultipledecisiontreestoreduceoverfittingand enhance generalization. Additionally, Random Forest efficientlyhandleshigh-dimensionalnetworktrafficdataand noisy features, making it highly suitable for real-time intrusion detection systems. Based on this comparative
analysis, Random Forest was selected as the core classificationmodelfortheproposedsystem.
TheproposedRandomForest-basedintrusiondetection systemwasevaluatedusingamergeddatasetcomprising approximately 2.83 million network flow records collectedfrommultipletrafficscenarios,includingbenign activity and diverse attack types such as DDoS, DoS variants, Port Scan, brute-force attacks, and web-based exploits.Asubsetofsixstatisticallysignificantflow-level features DestinationPort,FlowDuration,TotalForward Packets,TotalBackwardPackets,FlowBytes/s,andFlow Packets/s was used for training and testing after preprocessing.
The experimental results demonstrate an overall detection accuracy of 99.45%,highlighting thestrong discriminativecapabilityoftheproposedapproacheven when operating solely on traffic metadata. As shown in theconfusionmatrix,theclassifierachievesnear-perfect recognitionofmajorattackcategoriessuchasDDoS,DoS Hulk, Port Scan, FTP-Patator, and benign traffic, each attainingprecisionandrecallvaluesclosetounity.
However,comparativelylowerperformanceisobserved for rare classes such as Web Attack–Brute Force, Web Attack–SQLInjection,andWebAttack–XSSduetosevere classimbalanceinthedataset.Despitethis,theweighted average F1-score remains 0.99, confirming that the systemmaintainsrobustperformanceacrosslarge-scale trafficconditions.Theseresultsindicatethattheproposed metadata-drivenRandomForestmodelishighlyeffective forreal-timecyber-threatdetectioninencryptednetwork environments.


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Theproposedsystemdemonstratesaneffectiveapproach for detecting cyber threats in encrypted network traffic without relying on packet decryption. By focusing on metadataanalysisandmachinelearning,thesystemisable toidentifyabnormalbehaviorwhilepreservinguserprivacy andavoidingtheoverheadoftraditionalinspectionmethods. Real time classification, automated alerting, and an interactivedashboardprovidecontinuousvisibilityinto network activity, allowing users to respond quickly to suspiciousevents.Thecombinationoflivemonitoringanda trainedRandomForestmodelensuresreliabledetection acrossmultipleattacktypes.Overall,thesystemoffersa modern,lightweight,andpracticalsolutionthatenhances network security in environments where encryption is widely used, and it lays the groundwork for further improvements in intelligent, privacy-conscious threat detection.
Itgivesusimmensepleasuretoexpressourdeepsenseof gratitude to Dr. Pradipkumar Dixit, Principal, East Point CollegeofEngineeringandTechnology,Bengaluru,forhis constant encouragement and support throughout the duration of this work. We would also like to extend our sincere gratitude to Dr. I. Manimozhi, Head of the Department, Department of Computer Science and Engineering, EPCET, for her continuous guidance, motivation,andvaluablesuggestionsduringthecourseof thisproject.Wearetrulythankfultoourguide,Mrs.Madhu ShreeR,forherexpertmentorship,patience,andinsightful feedback, which greatly contributed to the successful completionofourproject.Wealsoappreciatethesupport ofallfacultymembers,staff,andourpeerswhohelpedus directly or indirectly. Their cooperation and encouragementmadethisworkpossible

Fig.6.3illustratesthereceiveroperatingcharacteristic (ROC)curvesobtainedfortheproposedRandomForestbasedintrusiondetectionsystem.Bothmicro-averageand macro-average ROC curves achieve an area under the curve(AUC)of1.00,indicatingexcellentclassseparability and highly reliable discrimination between benign and malicious network flows. The near-perfect ROC performancedemonstratestheeffectivenessofmetadatadriven feature extraction combined with ensemble learning for encrypted traffic analysis. These results furtherconfirmthesuitabilityoftheproposedsystemfor real-timecyber-threatmonitoringandprevention.
[1] B. Anderson and D. McGrew, “Identifying encrypted malware traffic with contextual flow data,” in Proc. ACM InternetMeasurementConf.(IMC),2016,pp.1–14.
[2]M.Shafiq,X.Yu,andD.Li,“Encryptedtrafficclassification usingmachinelearning:Asurvey,”IEEECommun.Surveys Tuts.,vol.22,no.3,pp.1881–1906,2020.
[3]M.Lotfollahi,M.J.Siavoshani,R.S.Moshkenani,andM. Saberian, “Deep packet: A novel approach for encrypted trafficclassificationusingdeeplearning,”IEEETrans.Netw. Sci.Eng.,vol.5,no.2,pp.1–13,2018.
[4]G.Aceto,D.Ciuonzo,A.Montieri,andA.Pescapé,“Mobile encryptedtrafficclassificationusingdeeplearning,”Comput. Netw.,vol.154,pp.1–13,2019.
[5] Canadian Institute for Cybersecurity, “CICIDS 2018: Intrusion detection evaluation dataset,” Univ. of New Brunswick,Fredericton,NB,Canada,2018.
[6] I. A. Alwhbi, C. C. Zou, and R. N. Alharbi, “Encrypted networktrafficanalysisandclassificationutilizingmachine learning,”Sensors,vol.24,no.3,pp.1–18,2024.
[7]T.Xu,H.Zhang,andF.Li,“Featureminingforencrypted malicious traffic detection using deep learning,” arXiv preprint,2023.
[8]A.Mareedu,“Machinelearningforsecurenetworktraffic analysis: From flow classification to encrypted threat detection,”ESP-IJACT,2025.
[9] E. C. Neto, S. Iqbal, and S. Buffett, “Deep learning for intrusiondetectioninemergingnetworks:Acomprehensive review,”arXivpreprint,2025.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
[10]R.AlshammariandN.Zaman,“Encryptednetworktraffic classificationbasedonmachinelearning,”AinShamsEng.J., vol.15,no.1,pp.1–14,2024.
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072 © 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008