Dependency-Centric Security Analysis for Lateral Communication in Data Center Environments

Authors

  • Daan van der Meer Department of Computer Science, Delft University of Technology, Delft, Netherlands Author
  • Sophie de Vries Department of Computer Science, Delft University of Technology, Delft, Netherlands Author
  • Thomas Jansen Department of Computer Science, Delft University of Technology, Delft, Netherlands Author

DOI:

https://doi.org/10.52152/

Keywords:

Data Center Security, East-West Traffic, Network Anomaly Detection, Lateral Movement, Ensemble Learning, SHAP, Explainable Intrusion Detection

Abstract

Data center networks generate large volumes of east-west traffic among servers, virtual machines, containers, and storage nodes. Abnormal east-west communication may indicate lateral movement, credential misuse, service probing, or compromised internal hosts. Traditional perimeter-based intrusion detection systems are less effective in this scenario because malicious traffic often remains inside the data center. This study proposes an interpretable ensemble learning framework for detecting east-west traffic anomalies in data center networks. The proposed model combines Histogram Gradient Boosting, Random Forest, and LightGBM through a confidence-weighted voting strategy. To improve transparency, SHAP is used to explain how flow dependency features contribute to anomaly decisions. Experiments are conducted on a simulated data center traffic environment with 320 virtual hosts, 48 application services, and 6 storage clusters. The dataset contains 4.27 million labeled flow records collected under normal workload migration, database synchronization, internal scanning, lateral movement, abnormal service discovery, and privilege-escalation traffic. After preprocessing, 52 features are extracted, including service-call frequency, host-pair communication persistence, internal port diversity, failed connection ratio, flow burst density, and cross-segment byte imbalance. The proposed framework achieves 98.29% accuracy, 97.64% F1-score, and 98.91% AUC in binary anomaly detection. In multi-class classification, it obtains a macro-F1 of 96.18% across five internal attack categories. Compared with a single LightGBM classifier, the ensemble model reduces false positives by 12.7% and improves detection recall for lateral movement traffic by 3.82%. SHAP analysis shows that abnormal host-pair persistence, sudden port diversity expansion, failed internal connections, and cross-segment byte imbalance are the most important indicators of suspicious east-west traffic. The results indicate that explainable ensemble learning can improve internal threat detection and provide interpretable evidence for data center security operations.

Downloads

Published

2026-08-20

Issue

Section

Articles

Similar Articles

21-30 of 78

You may also start an advanced similarity search for this article.