SearcharxivSearch

arXiv subjects

Javeriah Saleem

Publications and source records attributed to Javeriah Saleem.

3 recordsLinked to original sources

Behavioral Information Leakage in Darknet Traffic: A Multi-Channel Analysis Across Anonymity Networks

Existing darknet traffic classification studies largely emphasize predictive accuracy while offering limited insight into the behavioral mechanisms that make encrypted services distinguishable. This paper proposes a behavioral information leakage framework that decomposes flow-level traffic into control, structural, and rhythmic descriptor groups across Tor, I2P, FreeNet, and ZeroNet. The framework combines normalized mutual information analysis with Random Forest-based predictive validation, structural-rhythmic interaction analysis, and cross-network service-variability evaluation under leakage-safe repeated stratified cross-validation. Results show that behavioral leakage varies considerably across anonymity networks. Tor achieves the highest service separability, with a Macro-F1 of 0.7165 and cumulative normalized leakage of 3.9461, whereas FreeNet exhibits the lowest combined leakage of 0.8744. Packet-size organization, directional exchange imbalance, packet tempo, and silence-burst behavior emerge as the main leakage mechanisms. The combined structural-rhythmic representation consistently provides the strongest within-network performance, while leave-one-network-out evaluation reveals limited transferability across anonymity architectures. The proposed Service Variability Index and Leakage Variability Index further show that video exhibits consistent network-specific separability, whereas chat and email demonstrate greater variability across anonymity-network pairs.

cs.CR

Open-World Darknet Traffic Recognition Under Leave-One-Service-Out Evaluation

Darknet traffic recognition is critical for cyber threat intelligence, as anonymity networks are often used to conceal malicious activity. However, most existing studies rely on closed-world evaluation, assuming all service categories are known during training and testing, which is unrealistic in real-world environments. This paper presents an open-world darknet traffic classification framework using leave-one-service-out evaluation and uncertainty-aware classification with Random Forest and XGBoost models. Experimental results demonstrate significant performance degradation when transitioning from closed-world to open-world settings, demonstrating that closed-world evaluation substantially overestimates deployment robustness. For example, XGBoost Macro-F1 decreases from 88.8% to 46.1% in the I2P environment, while Random Forest performance drops from 87.4% to 45.7%. Although uncertainty-based rejection slightly improves robustness, strong behavioral similarity between known and unknown services leads to frequent misclassification. Semantic absorption analysis further shows that FreeNet video traffic is classified as browsing traffic with an 88.1% assignment rate, while I2P peer-to-peer traffic is absorbed into FTP-related behavior with an 83.4% assignment rate. The findings demonstrate that behavioral overlap remains a major challenge for reliable open-world darknet traffic classification.

cs.CR

Darknet Traffic Analysis A Systematic Literature Review

The primary objective of an anonymity tool is to protect the anonymity of its users through the implementation of strong encryption and obfuscation techniques. As a result, it becomes very difficult to monitor and identify users activities on these networks. Moreover, such systems have strong defensive mechanisms to protect users against potential risks, including the extraction of traffic characteristics and website fingerprinting. However, the strong anonymity feature also functions as a refuge for those involved in illicit activities who aim to avoid being traced on the network. As a result, a substantial body of research has been undertaken to examine and classify encrypted traffic using machine learning techniques. This paper presents a comprehensive examination of the existing approaches utilized for the categorization of anonymous traffic as well as encrypted network traffic inside the darknet. Also, this paper presents a comprehensive analysis of methods of darknet traffic using machine learning techniques to monitor and identify the traffic attacks inside the darknet.

cs.CR