Dependency-Centric Security Analysis for Lateral Communication in Data Center Environments
DOI:
https://doi.org/10.52152/Keywords:
Data Center Security, East-West Traffic, Network Anomaly Detection, Lateral Movement, Ensemble Learning, SHAP, Explainable Intrusion DetectionAbstract
Data center networks generate large volumes of east-west traffic among servers, virtual machines, containers, and storage nodes. Abnormal east-west communication may indicate lateral movement, credential misuse, service probing, or compromised internal hosts. Traditional perimeter-based intrusion detection systems are less effective in this scenario because malicious traffic often remains inside the data center. This study proposes an interpretable ensemble learning framework for detecting east-west traffic anomalies in data center networks. The proposed model combines Histogram Gradient Boosting, Random Forest, and LightGBM through a confidence-weighted voting strategy. To improve transparency, SHAP is used to explain how flow dependency features contribute to anomaly decisions. Experiments are conducted on a simulated data center traffic environment with 320 virtual hosts, 48 application services, and 6 storage clusters. The dataset contains 4.27 million labeled flow records collected under normal workload migration, database synchronization, internal scanning, lateral movement, abnormal service discovery, and privilege-escalation traffic. After preprocessing, 52 features are extracted, including service-call frequency, host-pair communication persistence, internal port diversity, failed connection ratio, flow burst density, and cross-segment byte imbalance. The proposed framework achieves 98.29% accuracy, 97.64% F1-score, and 98.91% AUC in binary anomaly detection. In multi-class classification, it obtains a macro-F1 of 96.18% across five internal attack categories. Compared with a single LightGBM classifier, the ensemble model reduces false positives by 12.7% and improves detection recall for lateral movement traffic by 3.82%. SHAP analysis shows that abnormal host-pair persistence, sudden port diversity expansion, failed internal connections, and cross-segment byte imbalance are the most important indicators of suspicious east-west traffic. The results indicate that explainable ensemble learning can improve internal threat detection and provide interpretable evidence for data center security operations.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 China and WTO Review

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
