Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features

被引:12
|
作者
Hong, Yueping [1 ]
Li, Qi [1 ]
Yang, Yanqing [1 ]
Shen, Meng [2 ]
机构
[1] Beijing Univ Posts & Telecommun, 10 Xitucheng Rd, Beijing, Peoples R China
[2] Beijing Inst Technol, 5 Yard,Zhong Guan Cun South St, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Malicious traffic; Encrypted traffic; SSL; TLS; Multi-view features; CLASSIFICATION; REPRESENTATION;
D O I
10.1016/j.ins.2023.119229
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
At present, the TLS cryptographic protocol is widely deployed. While protecting the security and integrity of transmitted information, it also makes the detection of malicious behavior more difficult. In recent years, researchers have proposed many encrypted malicious traffic detection methods. However, the existing approaches have some shortcomings. Firstly, although researchers have extracted multi-view features from different aspects, which can be divided into vectorized features based on feature engineering and image features based on original data, existing methods cannot fully integrate the features of different forms of expression. Secondly, most of the existing methods do not fully analyze the correlation between different encrypted traffic. Thirdly, the existing methods based on correlation analysis have low processing efficiency and cannot be applied to real networks. In the paper, we present MalDiscovery, a novel technique to discover encrypted malicious traffic to address all the above issues. For encrypted malicious traffic, MalDiscovery constructs an attribute KNN graph, in which encrypted sessions are used as nodes to construct a KNN graph according to the similarity of image features, and vectorized features are used as attributes of corresponding nodes. After that, the GraphSAGE model is used to collect relevant node information through correlation analysis to enrich the embeddings of each node. Finally, we achieve the accurate binary classification of nodes in the graph based on richer embeddings. We use extensive experiments to evaluate the proposed method, and the experiment results show that MalDiscovery can achieve an accuracy of about 99.9%, significantly outperforming all compared methods.
引用
收藏
页数:14
相关论文
共 50 条
  • [21] Multi-view Graph Embedding with Hub Detection for Brain Network Analysis
    Ma, Guixiang
    Lu, Chun-Ta
    He, Lifang
    Yu, Philip S.
    Ragin, Ann B.
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2017, : 967 - 972
  • [22] Encrypted Malicious Traffic Detection Based on Word2Vec
    Ferriyan, Andrey
    Thamrin, Achmad Husni
    Takeda, Keiji
    Murai, Jun
    ELECTRONICS, 2022, 11 (05)
  • [23] Saliency detection via multi-view graph based saliency optimization
    Xiao, Yun
    Jiang, Bo
    Zheng, Aihua
    Zhou, Aiwu
    Hussainb, Amir
    Tang, Jin
    NEUROCOMPUTING, 2019, 351 : 156 - 166
  • [24] Semi-Supervised Encrypted Malicious Traffic Detection Based on Multimodal Traffic Characteristics
    Liu, Ming
    Yang, Qichao
    Wang, Wenqing
    Liu, Shengli
    SENSORS, 2024, 24 (20)
  • [25] Mobile Application Identification Over HTTPS Traffic Based on Multi-view Features
    Tian, Mao
    Chang, Peng
    Sang, Yafei
    Zhang, Yongzheng
    Li, Shuhao
    2019 26TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2019, : 73 - 79
  • [26] Multi-view Graph Regularized Discriminant Analysis
    Chen, Shuangyue
    Wang, Lei
    Ji, Hongbing
    Zhao, Jie
    Wang, Yixin
    Li, Miao
    Li, Danping
    2017 CHINESE AUTOMATION CONGRESS (CAC), 2017, : 5192 - 5196
  • [27] Bipartite Graph Based Multi-View Clustering
    Li, Lusi
    He, Haibo
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2022, 34 (07) : 3111 - 3125
  • [28] Encrypted Malware Traffic Detection via Graph-based Network Analysis
    Fu, Zhuoqun
    Liu, Mingxuan
    Qin, Yue
    Zhang, Jia
    Zou, Yuan
    Yin, Qilei
    Li, Qi
    Duan, Haixin
    PROCEEDINGS OF 25TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2022, 2022, : 495 - 509
  • [29] Efficient Graph Based Multi-view Learning
    Hu, Hengtong
    Hong, Richang
    Fu, Weijie
    Wang, Meng
    MULTIMEDIA MODELING (MMM 2019), PT I, 2019, 11295 : 691 - 703
  • [30] AGAE: Unsupervised Anomaly Detection for Encrypted Malicious Traffic
    Wang, Hao
    Wang, Ye
    Gu, Zhaoquan
    Jia, Yan
    WEB AND BIG DATA, APWEB-WAIM 2024, PT IV, 2024, 14964 : 448 - 464