Back to Search View Original Cite This Article

Abstract

<title>Abstract</title> <p>Near-perfect supervised performance on firewall logs can reflect deployed decision traces rather than independent threat detection. This study analyzes 1,048,576 Palo Alto traffic-log records with Allow, Drop, and Deny labels from a tool-capped 46-minute window. Direct label-source fields are excluded, and established tree ensembles serve as diagnostic instruments. A model-free audit finds seven minimum four-field determining sets in the all-field view, each including Source Port and session-end Bytes. Although 64.7 to 71.4% of rows occupy singleton key contexts, exact agreement persists in repeated contexts; train-only discovery retains exact seen-context agreement, but its test coverage is limited. Cardinality-preserving controls break exactness, and within a reduced 17-field view the best four-field subset reaches 99.9713% empirical agreement without exact determination. XGBoost and LightGBM reconstruct the proxy-rich core labels exactly, while removing volume and duration yields 0.9962 macro-F1. A stricter proxy-minimal view reaches 0.95 with XGBoost but is unstable with LightGBM. On identical application/category held-out rows, macro-F1 rises from 0.673 with ordinal LightGBM to 0.992 with native-categorical CatBoost. Temperature scaling changes fixed-threshold queue behavior materially across the two pipelines, making confidence-only review representation- and calibration-dependent. Marginal conformal summaries hide rare-Deny undercoverage in the random-split lineage, whereas an unscaled ordinal queue misses most context-shift errors. A public instantiation from the University of California, Irvine (UCI) Machine Learning Repository reproduces high reconstructability and rare-class collapse only for schema-independent components. These results support retrospective, claim-bounded decision reconstruction and simulated uncertainty diagnostics within one export, not attack detection, causal policy recovery, or cross-environment generalization.</p>

Show More

Keywords

from view exact agreement lightgbm

Related Articles

PORE

About

Connect