A deep learning-based framework to identify and characterise heterogeneous secure network traffic

被引:3
作者
Ul Islam, Faiz [1 ]
Liu, Guangjie [2 ]
Liu, Weiwei [1 ]
ul Haq, Qazi Mazhar [3 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Automat, Nanjing, Peoples R China
[2] Nanjing Univ Informat Sci & Technol, Sch Elect & Informat Engn, Nanjing 210044, Peoples R China
[3] Natl Univ Sci & Technol, Mil Coll Signals, Dept Comp Software Engn, Islamabad, Pakistan
基金
中国国家自然科学基金;
关键词
deep learning; encrypted network traffic; machine learning; network traffic classification; TOR network; virtual private network (VPN); CLASSIFICATION; INTERNET; IDENTIFICATION;
D O I
10.1049/ise2.12095
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The evergrowing diversity of encrypted and anonymous network traffic makes network management more formidable to manage the network traffic. An intelligent system is essential to analyse and identify network traffic accurately. Network management needs such techniques to improve the Quality of Service and ensure the flow of secure network traffic. However, due to the usage of non-standard ports and encryption of data payloads, the classical port-based and payload-based classification techniques fail to classify the secured network traffic. To solve the above-mentioned problems, this paper proposed an effective deep learning-based framework employed with flow-time-based features to predict heterogeneous secure network traffic best. The state-of-the-art machine learning strategies (C4.5, random forest, and K-nearest neighbour) are investigated for comparison. The proposed 1D-CNN model achieved higher accuracy in classifying the heterogeneous secure network traffic. In the next step, the proposed deep learning model characterises the major categories (virtual private network traffic, the onion router network traffic, and plain encrypted network traffic) into several application types. The experimental results show the effectiveness and feasibility of the proposed deep learning framework, which yields improved predictive power compared to the state-of-the-art machine learning techniques employed for secure network traffic analysis.
引用
收藏
页码:294 / 308
页数:15
相关论文
共 51 条
[1]   DISTILLER: Encrypted traffic classification via multimodal multitask deep learning [J].
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Montieri, Antonio ;
Pescape, Antonio .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 183
[2]  
Afzal Z., 2020, NORDIC C SECURE IT S, P37
[3]  
[Anonymous], 2011, Technical report
[4]  
[Anonymous], 2017, P IEEE C NETW SOFTW, DOI DOI 10.1109/NETSOFT.2017.8004227
[5]  
Bagui S, 2017, Journal of Cyber Security Technology, V1, P108, DOI [10.1080/23742917.2017.1321891, 10.1080/23742917.2017.1321891, DOI 10.1080/23742917.2017.1321891]
[6]   A Big Data-Enabled Hierarchical Framework for Traffic Classification [J].
Bovenzi, Giampaolo ;
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Persico, Valerio ;
Pescape, Antonio .
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2020, 7 (04) :2608-2619
[7]  
Cao ZG, 2014, COMM COM INF SC, V490, P73
[8]  
Chollet F., 2015, keras. io
[9]  
Cisco: Cisco Encrypted Traffic Analytics, 2019, CISCO CISCO ENCRYPTE
[10]  
Diab WB, 2007, WMUNEP'07: PROCEEDINGS OF THE THIRD ACM WORKSHOP ON WIRELESS MULTIMEDIA NETWORKING AND PERFORMANCE MODELING, P92