ATVITSC: A Novel Encrypted Traffic Classification Method Based on Deep Learning

被引:2
|
作者
Liu, Ya [1 ,2 ]
Wang, Xiao [1 ]
Qu, Bo [3 ]
Zhao, Fengyu [4 ]
机构
[1] Univ Shanghai Sci & Technol, Sch Opt Elect & Comp Engn, Shanghai 200093, Peoples R China
[2] CTIHE, Lion Rock Labs Cyberspace Secur, Hong Kong, Peoples R China
[3] Guangdong Univ Sci & Technol, Sch Comp Sci, Dongguan 523083, Peoples R China
[4] Shanghai Publishing & Printing Coll, Dept Informat & Intelligence Engn, Shanghai 200093, Peoples R China
基金
中国国家自然科学基金;
关键词
Feature extraction; Cryptography; Spatiotemporal phenomena; Data mining; Transformers; Payloads; Telecommunication traffic; Encrypted traffic classification; self-attention mechanism; a dynamic weighting mechanism; spatialtemporal network;
D O I
10.1109/TIFS.2024.3433446
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The increasing prevalence of encrypted communication on the modern internet has presented new challenges for traffic classification and network management. Traditional traffic classification methods cannot handle encrypted traffic effectively. Meanwhile, many existing methods either rely on hand-crafted features or fail to extract the underlying interaction patterns between data packets adequately. In this paper, we propose a novel encrypted traffic classification method called the Attention-based Vision Transformer and Spatiotemporal for Traffic Classification (ATVITSC). In the preprocessing stage, packet-level images within a session, generated from the payload of data packets, are combined into a session image to mitigate information confusion. In the classification stage, session images are first processed by the packet vision transformer (PVT) module, which employs the transformer encoder and multi-head self-attention mechanism, to capture the global features. In parallel, session images are also processed by the spatiotemporal feature extraction (STFE) module, where spatial features of packets are extracted by the convolution operation with the attention mechanism and temporal features between packets are then combined by the bidirectional Long Short-Term Memory (LSTM). The global and spatiotemporal features are fused in the feature fusion classification (FFC) module by a dynamic weighting mechanism and encrypted traffic is finally classified based on the fused features. Comprehensive experiments on various types of encrypted traffic, including virtual private network (VPN), onion router (Tor), malicious traffic, and mobile traffic, show that the ATVITSC successfully improves the macro-f1 scores to 97.88%, 98.79%, 99.67%, 94.90%, respectively. The results also reveal that the ATVITSC exhibits better classification performance and generalization ability than the state-of-the-art methods.
引用
收藏
页码:9374 / 9389
页数:16
相关论文
共 50 条
  • [1] A Novel Multimodal Deep Learning Framework for Encrypted Traffic Classification
    Lin, Peng
    Ye, Kejiang
    Hu, Yishen
    Lin, Yanying
    Xu, Cheng-Zhong
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2023, 31 (03) : 1369 - 1384
  • [2] An Efficient Deep Learning Method for Encrypted Traffic Classification on the Web
    Soleymanpour, Shiva
    Sadr, Hossein
    Beheshti, Homayoun
    2020 6TH INTERNATIONAL CONFERENCE ON WEB RESEARCH (ICWR), 2020, : 209 - 216
  • [3] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Lotfollahi, Mohammad
    Siavoshani, Mahdi Jafari
    Zade, Ramin Shirali Hossein
    Saberian, Mohammdsadegh
    SOFT COMPUTING, 2020, 24 (03) : 1999 - 2012
  • [4] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Mohammad Lotfollahi
    Mahdi Jafari Siavoshani
    Ramin Shirali Hossein Zade
    Mohammdsadegh Saberian
    Soft Computing, 2020, 24 : 1999 - 2012
  • [5] End-to-end encrypted network traffic classification method based on deep learning
    Tian Shiming
    Gong Feixiang
    Mo Shuang
    Li Meng
    Wu Wenrui
    Xiao Ding
    TheJournalofChinaUniversitiesofPostsandTelecommunications, 2020, 27 (03) : 21 - 30
  • [6] End-to-end encrypted network traffic classification method based on deep learning
    Tian S.
    Gong F.
    Mo S.
    Li M.
    Wu W.
    Xiao D.
    Journal of China Universities of Posts and Telecommunications, 2020, 27 (03): : 21 - 30
  • [7] Deep Learning for Encrypted Traffic Classification: An Overview
    Rezaei, Shahbaz
    Liu, Xin
    IEEE COMMUNICATIONS MAGAZINE, 2019, 57 (05) : 76 - 81
  • [8] Mobile Encrypted Traffic Classification Using Deep Learning
    Aceto, Giuseppe
    Ciuonzo, Domenico
    Montieri, Antonio
    Pescape, Antonio
    2018 NETWORK TRAFFIC MEASUREMENT AND ANALYSIS CONFERENCE (TMA), 2018,
  • [9] A Deep Learning-Based Encrypted VPN Traffic Classification Method Using Packet Block Image
    Sun, Weishi
    Zhang, Yaning
    Li, Jie
    Sun, Chenxing
    Zhang, Shuzhuang
    ELECTRONICS, 2023, 12 (01)
  • [10] BFCN: A Novel Classification Method of Encrypted Traffic Based on BERT and CNN
    Shi, Zhaolei
    Luktarhan, Nurbol
    Song, Yangyang
    Tian, Gaoqi
    ELECTRONICS, 2023, 12 (03)