{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T13:45:11Z","timestamp":1781790311677,"version":"3.54.5"},"reference-count":63,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2018,11,22]],"date-time":"2018-11-22T00:00:00Z","timestamp":1542844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["BDCC"],"abstract":"<jats:p>A Security Operations Center (SOC) can be defined as an organized and highly skilled team that uses advanced computer forensics tools to prevent, detect and respond to cybersecurity incidents of an organization. The fundamental aspects of an effective SOC is related to the ability to examine and analyze the vast number of data flows and to correlate several other types of events from a cybersecurity perception. The supervision and categorization of network flow is an essential process not only for the scheduling, management, and regulation of the network\u2019s services, but also for attacks identification and for the consequent forensics\u2019 investigations. A serious potential disadvantage of the traditional software solutions used today for computer network monitoring, and specifically for the instances of effective categorization of the encrypted or obfuscated network flow, which enforces the rebuilding of messages packets in sophisticated underlying protocols, is the requirements of computational resources. In addition, an additional significant inability of these software packages is they create high false positive rates because they are deprived of accurate predicting mechanisms. For all the reasons above, in most cases, the traditional software fails completely to recognize unidentified vulnerabilities and zero-day exploitations. This paper proposes a novel intelligence driven Network Flow Forensics Framework (NF3) which uses low utilization of computing power and resources, for the Next Generation Cognitive Computing SOC (NGC2SOC) that rely solely on advanced fully automated intelligence methods. It is an effective and accurate Ensemble Machine Learning forensics tool to Network Traffic Analysis, Demystification of Malware Traffic and Encrypted Traffic Identification.<\/jats:p>","DOI":"10.3390\/bdcc2040035","type":"journal-article","created":{"date-parts":[[2018,11,22]],"date-time":"2018-11-22T09:18:25Z","timestamp":1542878305000},"page":"35","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["The Next Generation Cognitive Security Operations Center: Network Flow Forensics Using Cybersecurity Intelligence"],"prefix":"10.3390","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1330-5228","authenticated-orcid":false,"given":"Konstantinos","family":"Demertzis","sequence":"first","affiliation":[{"name":"Department of Civil Engineering, School of Engineering, Democritus University of Thrace, Xanthi 67100, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Panayiotis","family":"Kikiras","sequence":"additional","affiliation":[{"name":"Department of Computer Science, School of Science, University of Thessaly, Lamia 35131, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nikos","family":"Tziritas","sequence":"additional","affiliation":[{"name":"Research Center for Cloud Computing, Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen 518000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3828-4136","authenticated-orcid":false,"given":"Salvador Llopis","family":"Sanchez","sequence":"additional","affiliation":[{"name":"Communications Department, Universitat Politecnica de Valencia, Valencia 46022, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lazaros","family":"Iliadis","sequence":"additional","affiliation":[{"name":"Department of Civil Engineering, School of Engineering, Democritus University of Thrace, Xanthi 67100, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2018,11,22]]},"reference":[{"key":"ref_1","unstructured":"CISCO (2008). WAN and Application Optimization Solution Guide, CISCO Press. Available online: www.cisco.com\/c\/en\/us\/td\/docs\/nsite\/enterprise\/wan\/wan_optimization\/wan_opt_sg.pdf."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1109\/MNET.2011.5772054","article-title":"Network traffic monitoring, analysis and anomaly detection [Guest Editorial]","volume":"25","author":"Wang","year":"2011","journal-title":"IEEE Netw."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Rudd, E., Rozsa, A., Gunther, M., and Boult, T. (arXiv, 2016). A Survey of Stealth Malware: Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions, arXiv.","DOI":"10.1109\/COMST.2016.2636078"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Zhang, H., Papadopoulos, C., and Massey, D. (2013, January 14\u201319). Detecting encrypted botnet traffic. Proceedings of the 2013 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Turin, Italy.","DOI":"10.1109\/INFCOM.2013.6567180"},{"key":"ref_5","unstructured":"William, H., Teukolsky, S.A., Vetterling, W.T., and Flannery, B.P. (2007). Section 16.5. Support Vector Machines. Numerical Recipes: The Art of Scientific Computing, Cambridge University Press. [3rd ed.]."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Hubel, D.H., and Wiesel, T.N. (2005). Brain and Visual Perception: The Story of a 25-Year Collaboration, Oxford University Press.","DOI":"10.1093\/acprof:oso\/9780195176186.003.0002"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random Forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"2135","DOI":"10.1214\/07-AOS537","article-title":"Choice of neighbor order in nearest-neighbor classification","volume":"36","author":"Hall","year":"2008","journal-title":"Ann. Stat."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"85","DOI":"10.3389\/fenvs.2017.00085","article-title":"Commentary: Aedes albopictus and Aedes japonicus\u2014Two invasive mosquito species with different temperature niches in Europe","volume":"5","author":"Demertzis","year":"2017","journal-title":"Front. Environ. Sci."},{"key":"ref_10","first-page":"45","article-title":"Ladon: A Cyber-Threat Bio-Inspired Intelligence Management System","volume":"3","author":"Demertzis","year":"2016","journal-title":"J. Appl. Math. Bioinform."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"322","DOI":"10.1007\/978-3-319-07869-4_30","article-title":"Evolving Computational Intelligence System for Malware Detection","volume":"Volume 178","author":"Demertzis","year":"2014","journal-title":"Advanced Information Systems Engineering Workshops"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Llopis, S., Hingant, J., P\u00e9rez, I., Esteve, M., Carvajal, F., Mees, W., and Debatty, T. (2018, January 22\u201323). A comparative analysis of visualisation techniques to achieve cyber situational awareness in the military. Proceedings of the 2018 International Conference on Military Communications and Information Systems (ICMCIS), Warsaw, Poland.","DOI":"10.1109\/ICMCIS.2018.8398693"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2991","DOI":"10.1109\/COMST.2016.2566669","article-title":"A Survey on Regular Expression Matching for Deep Packet Inspection: Applications, Algorithms, and Hardware Platforms","volume":"18","author":"Xu","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Gammerman, A., Vovk, V., and Papadopoulos, H. (2015). Evolving Smart URL Filter in a Zone-based Policy Firewall for Detecting Algorithmically Generated Malicious Domains. Statistical Learning and Data Sciences, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-319-17091-6"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1663","DOI":"10.1109\/TNET.2012.2184552","article-title":"Detecting Algorithmically Generated Domain-Flux Attacks with DNS Traffic Analysis","volume":"20","author":"Yadav","year":"2012","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_16","unstructured":"Hayes, J. (arXiv, 2016). Traffic Confirmation Attacks Despite Noise, arXiv."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Mercaldo, F., and Martinelli, F. (2017, January 20\u201322). Tor traffic analysis and identification. Proceedings of the 2017 AEIT International Annual Conference, Cagliari, Italy.","DOI":"10.23919\/AEIT.2017.8240548"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Montieri, A., Ciuonzo, D., Aceto, G., and Pescap\u00e9, A. (2017, January 4\u20138). Anonymity Services Tor, I2P, JonDonym: Classifying in the Dark. Proceedings of the 2017 29th International Teletraffic Congress (ITC 29), Genoa, Italy.","DOI":"10.23919\/ITC.2017.8064342"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Backes, M., Goldberg, I., Kate, A., and Mohammadi, E. (2012, January 25\u201327). Provably secure and practical onion routing. Proceedings of the 2012 IEEE 25th Computer Security Foundations Symposium (CSF), Cambridge, MA, USA.","DOI":"10.1109\/CSF.2012.32"},{"key":"ref_20","first-page":"255","article-title":"Secure Socket Layer and its Security Analysis","volume":"7","author":"Deepika","year":"2015","journal-title":"Netw. Commun. Eng."},{"key":"ref_21","unstructured":"Sideridis, A., Kardasiadou, Z., Yialouris, C., and Zorkadis, V. (2014). A Hybrid Network Anomaly and Intrusion Detection Approach Based on Evolving Spiking Neural Network Classification. E-Democracy, Security, Privacy and Trust in a Digital World, Springer. e-Democracy 2013; Communications in Computer and Information Science."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Daras, N., and Rassias, M. (2014). Bio-Inspired Hybrid Artificial Intelligence Framework for Cyber Security. Computation, Cryptography, and Network Security, Springer.","DOI":"10.1007\/978-3-319-18275-9"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Iliadis, L., Papazoglou, M., and Pohl, K. (2014). Bio-Inspired Hybrid Intelligent Method for Detecting Android Malware. Advanced Information Systems Engineering Workshops, Springer. CAiSE 2014. Lecture Notes in Business Information Processing.","DOI":"10.1007\/978-3-319-07869-4"},{"key":"ref_24","unstructured":"N\u00fa\u00f1ez, M., Nguyen, N., Camacho, D., and Trawi\u0144ski, B. (2015). SAME: An Intelligent Anti-Malware Extension for Android ART Virtual Machine. Computational Collective Intelligence, Springer. Lecture Notes in Computer Science."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/s40595-017-0095-3","article-title":"Computational Intelligence Anti-Malware Framework for Android OS","volume":"4","author":"Demertzis","year":"2017","journal-title":"Vietnam J. Comput. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/17512549.2017.1325401","article-title":"Anezakis, An innovative soft computing system for smart energy grids cybersecurity","volume":"12","author":"Demertzis","year":"2018","journal-title":"Adv. Build. Energy Res."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Scandariato, R., and Walden, J. (2012, January 21). Predicting vulnerable classes in an android application. Proceedings of the 4th International Workshop on Security Measurements and Metrics, Lund, Sweden.","DOI":"10.1145\/2372225.2372231"},{"key":"ref_28","unstructured":"Chin, E., Felt, A., Greenwood, K., and Wagner, D. (July, January 28). Analyzing inter-application communication in android. Proceedings of the 9th International Conference on Mobile Systems, Applications, and Services, Bethesda, MD, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., and Nadjm-Tehrani, S. (2011, January 17). Crowdroid: Behavior-based malware detection system for android. Proceedings of the 1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, Chicago, IL, USA.","DOI":"10.1145\/2046614.2046619"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Glodek, W., and Harang, R.R. (2013, January 18\u201320). Permissions-based Detection and Analysis of Mobile Malware Using Random Decision Forests. Proceedings of the 2013 IEEE Military Communications Conference, San Diego, CA, USA.","DOI":"10.1109\/MILCOM.2013.170"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1109\/TNSM.2013.022713.120250","article-title":"An effective network traffic classification method with unknown flow detection","volume":"10","author":"Zhang","year":"2013","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Joseph, G., and Nagaraja, S. (2014). On the reliability of network measurement techniques used for malware traffic analysis. Cambridge International Workshop on Security Protocols, Springer.","DOI":"10.1007\/978-3-319-12400-1_32"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Wang, H.T., Mao, C.H., Wu, K.P., and Lee, H.M. (2012, January 16\u201320). Real-time fast-flux identification via localized spatial geolocation detection. Proceedings of the IEEE Computer Software and Applications Conference (COMPSAC), Izmir, Turkey.","DOI":"10.1109\/COMPSAC.2012.35"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Tu, T.D., Guang, C., and Xin, L.Y. (2015, January 28\u201330). Detecting bot-infected machines based on analyzing the similar periodic DNS queries. Proceedings of the IEEE 2015 International Conference on Communications, Management and Telecommunications (ComManTel), DaNang, Vietnam.","DOI":"10.1109\/ComManTel.2015.7394256"},{"key":"ref_35","first-page":"2389","article-title":"Detection of fast-flux botnets through DNS traffic analysis","volume":"22","author":"Soltanaghaei","year":"2015","journal-title":"Sci. Iranica Trans. D Comput. Sci. Eng. Electr."},{"key":"ref_36","unstructured":"Wright, M.K., Adler, M., Levine, B.N., and Shields, C. (2002, January 6\u20138). An analysis of the degradation of anonymous protocols. Proceedings of the Network and Distributed Security Symposium, San Diego, CA, USA."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Shmatikov, V., and Wang, M.H. (2006, January 18\u201320). Timing analysis in low-latency mix networks: Attacks and defenses. Proceedings of the ESORICS, Hamburg, Germany.","DOI":"10.1007\/11863908_2"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Hsu, C.-H., Huang, C.-Y., and Chen, K.-T. (2010). Fast-flux bot detection in real time. International Workshop on Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/978-3-642-15512-3_24"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Haffner, P., Sen, S., Spatscheck, O., and Wang, D. (2005, January 22\u201326). ACAS: Auto-mated Construction of Application Signatures. Proceedings of the ACM SIGCOMM, Philadelphia, PA, USA.","DOI":"10.1145\/1080173.1080183"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Alshammari, R., and Zincir-Heywood, N.A. (2007, January 7\u201310). A flow-based approach for SSH traffic detection, Cybernetics, ISIC. Proceedings of the IEEE International Conference on Systems, Man and Cybernetics, Montreal, QC, Canada.","DOI":"10.1109\/ICSMC.2007.4414006"},{"key":"ref_41","unstructured":"Holz, T., Gorecki, C., Rieck, K., and Freiling, F. (2008, January 10\u201313). Measuring and detecting fast-flux service networks. Proceedings of the Network & Distributed System Security Symposium, San Diego, CA, USA."},{"key":"ref_42","first-page":"10","article-title":"A Model for Detecting Tor Encrypted Traffic using Supervised Machine Learning","volume":"7","author":"Almubayed","year":"2015","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Chaabane, A., Manils, P., and Kaafar, M.A. (2010, January 21\u201323). Digging into Anonymous Traffic: A Deep Analysis of the Tor Anonymizing Network. Proceedings of the 4th International Conference on Network and System Security (NSS), Helsinki, Finland.","DOI":"10.1109\/NSS.2010.47"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Chakravarty, S., Stavrou, A., and Keromytis, A.D. (2010). Traffic analysis against low-latency anonymity networks using available bandwidth estimation. European Symposium on Research in Computer Security, Springer.","DOI":"10.1007\/978-3-642-15497-3_16"},{"key":"ref_45","unstructured":"Chakravarty, S., Stavrou, A., and Keromytis, A.D. (December, January 30). Identifying Proxy Nodes in a Tor Anonymization Circuit. Proceedings of the 2nd Workshop on Security and Privacy in Telecommunications and Information Systems (SePTIS), Bali, Indonesia."},{"key":"ref_46","unstructured":"Mees, W., Llopis, S., and Debatty, T. (2016, January 3\u20134). Achieving cyber situation awareness through a multi-aspect 3D operational picture. Proceedings of the NATO IST-148 Symposium on Cyber Defense Situational Awareness, Sofia, Bulgaria."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Bonab, R.H., and Can, F. (2016, January 24\u201328). A Theoretical Framework on the Ideal Number of Classifiers for Online Ensembles in Data Streams. Proceedings of the 25th ACM International on Conference on Information and Knowledge Management, Indianapolis, IN, USA.","DOI":"10.1145\/2983323.2983907"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Zhou, Z.H. (2012). Ensemble Methods: Foundations and Algorithms, CRC Press.","DOI":"10.1201\/b12207"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Kuncheva, L. (2004). Combining Pattern Classifiers: Methods and Algorithms, Wiley.","DOI":"10.1002\/0471660264"},{"key":"ref_50","first-page":"1","article-title":"Ensemble methods in machine learning","volume":"Volume 1857","author":"Kittler","year":"2001","journal-title":"Multiple Classifier Systems"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"980","DOI":"10.1109\/TKDE.2004.29","article-title":"Multistrategy ensemble learning: Reducing error by combining ensemble learning techniques","volume":"16","author":"Webb","year":"2004","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"511","DOI":"10.3233\/IDA-2005-9602","article-title":"Selective fusion of heterogeneous classifiers","volume":"9","author":"Tsoumakas","year":"2005","journal-title":"Intell. Data Anal."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/34.824819","article-title":"Statistical pattern recognition: A review","volume":"22","author":"Mao","year":"2000","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"861","DOI":"10.1016\/j.patrec.2005.10.010","article-title":"An introduction to ROC analysis","volume":"Volume 27","author":"Fawcett","year":"2006","journal-title":"Pattern Recognition Letters"},{"key":"ref_55","unstructured":"Haining, W., Danlu, Z., and Kang, G.S. (2002, January 23\u201327). Detecting SYN flooding attacks. Proceedings of the Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies, New York, NY, USA."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Arndt, D.J., and Zincir-Heywood, A.N. (2011, January 11\u201315). A Comparison of Three Machine Learning Techniques for Encrypted Network Traffic Analysis. Proceedings of the 2011 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), Paris, France.","DOI":"10.1109\/CISDA.2011.5945941"},{"key":"ref_57","unstructured":"(2018, June 16). Contagiodump. Available online: http:\/\/contagiodump.blogspot.com\/."},{"key":"ref_58","unstructured":"(2018, July 20). Usma. Available online: https:\/\/www.usma.edu."},{"key":"ref_59","unstructured":"(2018, July 25). Netresec. Available online: https:\/\/www.netresec.com."},{"key":"ref_60","unstructured":"(2018, June 06). NetFlow. Available online: https:\/\/dan.arndt.ca."},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Sagduyu, E., and Ephremides, A. (2007, January 16\u201320). A Game-Theoretic Analysis of Denial of Service Attacks in Wireless Random Access. Proceedings of the 2007 5th International Symposium on Modeling and Optimization in Mobile, Ad Hoc and Wireless Networks and Workshops, Limassol, Cyprus.","DOI":"10.1109\/WIOPT.2007.4480053"},{"key":"ref_62","unstructured":"Sagduyu, Y.E., Berryt, R.A., and Ephremidesi, A. (June, January 31). Wireless jamming attacks under dynamic traffic uncertainty. Proceedings of the 8th International Symposium on Modeling and Optimization in Mobile, Ad Hoc, and Wireless Networks, Avignon, France."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Zhu, Q., Alpcan, T., Panaousis, E., Tambe, M., and Casey, W. (2016). On the Mitigation of Interference Imposed by Intruders in Passive RFID Networks. Decision and Game Theory for Security, Springer. GameSec 2016; Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-319-47413-7"}],"container-title":["Big Data and Cognitive Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-2289\/2\/4\/35\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T15:31:16Z","timestamp":1760196676000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-2289\/2\/4\/35"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,11,22]]},"references-count":63,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2018,12]]}},"alternative-id":["bdcc2040035"],"URL":"https:\/\/doi.org\/10.3390\/bdcc2040035","relation":{},"ISSN":["2504-2289"],"issn-type":[{"value":"2504-2289","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,11,22]]}}}