🤖 AI Summary
This study addresses the limitations of traditional intrusion detection systems in digital forensics, particularly their lack of traceability, reproducibility, and courtroom admissibility, as well as their inability to provide instance-level explanations. To overcome these challenges, the authors propose a forensically compliant intrusion detection framework aligned with judicial standards such as ISO/IEC 27037, which strictly segregates original evidence from analytical artifacts. The approach leverages Synthetic Data Vault (SDV) and CTGAN to generate synthetic network traffic for training an XGBoost classifier, while SHAP TreeExplainer enables instance-level attribution of attack behaviors. Experimental results demonstrate that synthetic data achieves a TSTR F1-macro score of 0.96 on CICIDS2017, and cross-dataset validation confirms that approximately 30 key features suffice to maintain detection performance. Critically, SHAP attributions exhibit high consistency between real and synthetic data, effectively preserving attack fingerprints while ensuring both high accuracy and forensic compliance.
📝 Abstract
Digital forensic investigations of network intrusions require analytical outputs that are traceable, reproducible, and court-defensible - requirements existing machine learning pipelines do not satisfy, since they treat original evidence as training data and produce opaque classifications without instance-level justification. This paper presents a forensic-oriented intrusion detection framework resolving both problems simultaneously, integrating synthetic data generation, binary classification, and explainability within a single pipeline governed by ISO/IEC 27037, 27041, 27042, and NIST SP 800-86.
The framework operationalises the ISO/IEC 27037 requirement for strict separation between original digital evidence and derived analytical artefacts. Original datasets are treated as immutable, hash-verified artefacts; all training operates on parameterized synthetic derivatives via SDV + CTGAN. XGBoost binary classification provides high-performance detection on tabular network flow data, and SHAP TreeExplainer produces instance-level feature attributions mapping statistical predictions to observable network behaviour for forensic reporting.
Train-on-Synthetic, Test-on-Real (TSTR) evaluation on CICIDS2017 achieves F1-macro = 0.96, within cross-validation variance of the real-data baseline (0.97). Kolmogorov-Smirnov testing confirms synthetic privacy preservation (mean |KS| = 0.38) alongside operational utility. Cross-dataset validation on UNSW-NB15 and Kitsune identifies feature space dimensionality as the primary determinant of synthetic training effectiveness, establishing a practical deployment boundary of approximately 30 numeric flow-level features. SHAP attributions for Brute Force, Port Scan, and DoS attacks are consistent across real and synthetic instances, confirming synthetic training preserves forensically relevant attack fingerprints required for expert witness testimony.