MODELING AND FORECASTING INFORMATION SECURITY THREATS BASED ON TCP PACKET METADATA ANALYSIS AND ARTIFICIAL INTELLIGENCE METHODS FOR RECONSTRUCTING SOCIAL GRAPHS OF MESSENGER USERS
DOI:
https://doi.org/10.52754/16948610_2026_3_14%20Keywords:
cybersecurity, TCP metadata, deanonymization, social graph, artificial intelligence, machine learning, deep learning, graph neural network, threat prediction, information theoryAbstract
Modern intrusion detection systems based on signature analysis and classical machine learning methods exhibit fundamental limitations in detecting multi-stage targeted attacks (APTs) distributed across time and space. Transitioning from reactive detection to predictive modeling requires fundamentally new approaches that account not only for isolated events but also for the structural relationships between entities involved in information exchange. The issue of metadata leakage is of particular concern: even with end-to-end encryption of message content, a passive observer at the ISP level retains access to timestamps, sizes, and the direction of TCP packets, creating conditions for reconstructing user social graphs and predicting the progression of attacks.
References
Anderson, J.P. Computer Security Threat Monitoring and Surveillance / J.P. Anderson. - Fort Washington: James P. Anderson Co., 1980.
Denning, D.E. An Intrusion-Detection Model / D.E. Denning // IEEE Transactions on Software Engineering. - 1987. - Vol. SE-13, No. 2. - P. 222–232.
Tavallaee, M. A Detailed Analysis of the KDD CUP 99 Data Set / M. Tavallaee, E. Bagheri, W. Lu, A.A. Ghorbani // CISDA. - 2009. - P. 1–6.
Sommer, R. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection / R. Sommer, V. Paxson // IEEE S&P. - 2010. - P. 305–316.
Buczak, A.L. A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection / A.L. Buczak, E. Guven // IEEE Communications Surveys & Tutorials. - 2016. - Vol. 18, No. 2. - P. 1153–1176.
Sharafaldin, I. Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization / I. Sharafaldin, A.H. Lashkari, A.A. Ghorbani // ICISSP. - 2018. - P. 108–116.
Lashkari, A.H. Characterization of Tor Traffic Using Time Based Features / A.H. Lashkari, G.D. Gil, M.S.I. Mamun, A.A. Ghorbani // ICISSP. - 2017. - P. 253–262.
Ferrag, M.A. Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study / M.A. Ferrag, L. Maglaras, S. Moschoyiannis, H. Janicke // Information Security Journal. - 2022. - Vol. 31, No. 2. - P. 108–139.
Moustafa, N. ToN_IoT Datasets: A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems / N. Moustafa // IEEE Access. - 2020. - Vol. 8. - P. 165130–165150.
Breiman, L. Random Forests / L. Breiman // Machine Learning. - 2001. - Vol. 45. - P. 5–32.
Chen, T. XGBoost: A Scalable Tree Boosting System / T. Chen, C. Guestrin // KDD. - 2016. - P. 785–794.
Kipf, T.N. Semi-Supervised Classification with Graph Convolutional Networks / T.N. Kipf, M. Welling // ICLR. - 2017.
Veličković, P. Graph Attention Networks / P. Veličković, G. Cucurull, A. Casanova, A. Romero, P. Liò, Y. Bengio // ICLR. - 2018.
Lo, W.W. E-GraphSAGE: A Graph Neural Network Based Intrusion Detection System for IoT / W.W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, M. Portmann // IEEE/IFIP NOMS. - 2022. - P. 1–9.
Caville, E. Anomal-E: A Self-Supervised Network Intrusion Detection System Based on Graph Neural Networks / E. Caville, W.W. Lo, S. Layeghy, M. Portmann // Knowledge-Based Systems. - 2022. - Vol. 258. - P. 110030.
Bai, S. An Empirical Evaluation of Generic Convolutional and Recurrent Networks for Sequence Modeling / S. Bai, J.Z. Kolter, V. Koltun // arXiv:1803.01271. - 2018.
Vaswani, A. Attention Is All You Need / A. Vaswani et al. // NeurIPS. - 2017. - P. 5998–6008.
Yu, W. LogBERT: Log Anomaly Detection via BERT / W. Yu, Z. Ge, P. Sun, J. Wang, W. Xu // IJCNN. - 2021. - P. 1–8.
Kim, J. Long Short Term Memory Recurrent Neural Network Classifier for Intrusion Detection / J. Kim, J. Kim, H.L.T. Thu, H. Kim // ICUIMC. - 2016. - Article 94.
Staudemeyer, R.C. Applying Long Short-Term Memory Recurrent Neural Networks to Intrusion Detection / R.C. Staudemeyer // South African Computer Journal. - 2015. - Vol. 56, No. 1. - P. 136–154.
Li, C.-Y. Identity Leakage in Encrypted IM Call Services: An Empirical Study of Metadata Correlation / C.-Y. Li // Future Internet. - 2026. - Vol. 18, No. 1. - Article 12.
Chen, J. NotiCorr: Exposing Social Relationships via Notification Traffic of Instant Messaging Applications / J. Chen, Z. Jiang, J. Yin, D. Hao, Z. Li, M. Du, Q. Liu // ICCS 2025. - 2025.
Mehavilla, L. Unveiling User Activities on Instant Messaging Platforms: A Study of Activity Fingerprinting through Traffic Analysis and Machine Learning Techniques / L. Mehavilla, J. García et al. // Knowledge-Based Systems. - 2026.
Aoun, T. Inferring Communication Pairs in End-to-End Encrypted Messaging Applications / T. Aoun. - M.S. Thesis, University of Illinois Urbana-Champaign, 2025.
Bora, C.B. Dalhousie NIMS Lab IMA Traffic Dataset 2025 / C.B. Bora, J.S. Weber, N. Zincir-Heywood // IEEE DataPort. - 2025. - DOI: 10.21227/rmg3-b562.
Soylu, A. A Hybrid Graph Neural Network Model for Predicting Cyber Attacks From Heterogeneous and Dynamic Network Data / A. Soylu // Semantic Scholar. - 2025.
TEAMS: Robust Dynamic Trust Evaluation Using Snapshot-Based Graph Neural Networks in On-line Social Networks // Neurocomputing. - 2026.
Ghosh, K.P. A Novel Deep Learning Framework with Temporal Attention Convolutional Networks for Intrusion Detection in IoT and IIoT Networks / K.P. Ghosh, M. Hasan, M.T.I. Robin et al. // Scientific Reports. - 2025.
Advanced Intrusion Detection in Internet of Things Using Graph Attention Networks // Scientific Reports. - 2025.
Graph Attention and Kolmogorov–Arnold Network Based Smart Grids Intrusion Detection // Scientific Reports. - 2025.
Lundberg, S.M. A Unified Approach to Interpreting Model Predictions / S.M. Lundberg, S.-I. Lee // NeurIPS. - 2017. - P. 4765–4774.
Goodfellow, I.J. Explaining and Harnessing Adversarial Examples / I.J. Goodfellow, J. Shlens, C. Szegedy // ICLR. - 2015.
Madry, A. Towards Deep Learning Models Resistant to Adversarial Attacks / A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu // ICLR. - 2018.
ENISA. Threat Landscape 2025. European Union Agency for Cybersecurity, 2025.
Verizon. Data Breach Investigations Report 2026. Verizon Business, 2026.
Асилбеков, Т., Имаралиев, О. (2025). Электронный документооборот в высших учебных заведениях кыргызской республики: современное состояние и перспективы развития. Вестник Ошского государственного университета, (2), 109–121. https://doi.org/10.52754/16948610_2025_2_10
Омаралиева Г.А., Мамасалиев А.А., Абдыкадыров С.К. (2026). Защита данных в распределённых и облачных серверных системах (на примере финансового сектора). Открытый журнал евразийских исследований, 3, 110-128. https://doi.org/10.65469/eijournal.2026.3.12
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Тынчтыкбек Асилбеков, Максатбек Орозов

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.



