Enhanced Few-Shot Malware Traffic Classification via Integrating Knowledge Transfer With Neural Architecture Search

被引:7
作者
Zhang, Xixi [1 ]
Wang, Qin [1 ]
Qin, Maoyang [1 ]
Wang, Yu [1 ]
Ohtsuki, Tomoaki [2 ]
Adebisi, Bamidele [3 ]
Sari, Hikmet [1 ]
Gui, Guan [1 ]
机构
[1] Nanjing Univ Posts & Telecommun, Coll Telecommun & Informat Engn, Nanjing 210003, Peoples R China
[2] Keio Univ, Dept Informat & Comp Sci, Yokohama, Kanagawa 2238522, Japan
[3] Manchester Metropolitan Univ, Fac Sci & Engn, Dept Engn, Manchester M1 5GD, England
关键词
Feature extraction; Malware; Task analysis; Knowledge transfer; Convolutional neural networks; Image edge detection; Data models; Malware traffic classification; cyber security; deep learning; neural architecture search; few-shot learning; NETWORK INTRUSION DETECTION; INTERNET; THINGS; MODEL;
D O I
10.1109/TIFS.2024.3396624
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malware traffic classification (MTC) is one of the important research topics in the field of cyber security. Existing MTC methods based on deep learning have been developed based on the assumption of enough high-quality samples and powerful computing resources. However, both are hard to obtain in real applications especially in availability of IoT. In this paper, we propose a few-shot MTC (FS-MTC) method combining knowledge transfer and neural architecture search (i.e. NAS-based FS-MTC) with limited training samples as well as acceptable computational resources, in order to mitigate the identified challenges. Specifically, our proposed method first converts the raw network traffic into traffic images through data pre-processing to serve as input data for the neural network. Second, we use neural architecture search to adaptively search for the effective feature extraction model on the source domain (including Edge-IIoTset, Bot-IoT, and benign USTC-TFC2016). Third, the searched model is pre-trained on source task to achieve the generic feature representation of malware traffic. Finally, we only use few-shot malware traffic samples to fine-tune the pre-trained model to quickly adapt to new types of MTC tasks in realistic network environments. The experimental results show that the proposed NAS-based FS-MTC method has great scalability and classification performance in different FS-MTC tasks, including 5-way K-shot USTC-TFC2016 dataset and 10-way K-shot CIC-IoT dataset. Compared with state-of-the-art methods in the field of malware classification, the proposed NAS-based FS-MTC has higher classification accuracy. Especially in the 1-shot case of the USTC-TFC2016 dataset, its average accuracy is as high as 86.91%.
引用
收藏
页码:5245 / 5256
页数:12
相关论文
共 50 条
  • [1] Few-Shot Automatic Modulation Classification Using Architecture Search and Knowledge Transfer in Radar-Communication Coexistence Scenarios
    Zhang, Xixi
    Wang, Yu
    Huang, Hao
    Lin, Yun
    Zhao, Haitao
    Gui, Guan
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (19): : 32067 - 32078
  • [2] Few-Shot Malware Traffic Classification Method Using Network Traffic and Meta Transfer Learning
    Guo, Hanyi
    Zhang, Xixi
    Wang, Yu
    Adebisi, Bamidele
    Gacanin, Haris
    Gui, Guan
    2022 IEEE 96TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2022-FALL), 2022,
  • [3] Few-Shot Object Detection via Knowledge Transfer
    Kim, Geonuk
    Jung, Hong-Gyu
    Lee, Seong-Whan
    2020 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2020, : 3564 - 3569
  • [4] Visual Classification of Malware by Few-shot Learning
    Tran, Kien
    Kubo, Masao
    Sato, Hiroshi
    PROCEEDINGS OF THE 2020 INTERNATIONAL CONFERENCE ON ARTIFICIAL LIFE AND ROBOTICS (ICAROB2020), 2020, : 770 - 774
  • [5] Dual selective knowledge transfer for few-shot classification
    Kai He
    Nan Pu
    Mingrui Lao
    Erwin M. Bakker
    Michael S. Lew
    Applied Intelligence, 2023, 53 : 27779 - 27789
  • [6] Dual selective knowledge transfer for few-shot classification
    He, Kai
    Pu, Nan
    Lao, Mingrui
    Bakker, Erwin M.
    Lew, Michael S.
    APPLIED INTELLIGENCE, 2023, 53 (22) : 27779 - 27789
  • [7] A Differentiable Architecture Search Approach for Few-Shot Image Classification
    He, Chunmao
    Zhang, Lingyun
    Huang, Songqing
    Zhang, Pingjian
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2022, PT IV, 2022, 13532 : 521 - 532
  • [8] Neural Architecture Search Using Differential Evolution in MAML Framework for Few-Shot Classification Problems
    Gulcu, Ayla
    Kus, Zeki
    METAHEURISTICS, MIC 2022, 2023, 13838 : 143 - 157
  • [9] From Data and Model Levels: Improve the Performance of Few-Shot Malware Classification
    Chai, Yuhan
    Qiu, Jing
    Yin, Lihua
    Zhang, Lejun
    Gupta, Brij B.
    Tian, Zhihong
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (04): : 4248 - 4261
  • [10] Integrating Knowledge Distillation With Learning to Rank for Few-Shot Scene Classification
    Liu, Yishu
    Zhang, Liqiang
    Han, Zhengzhuo
    Chen, Conghui
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60