VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network

被引:0
作者
Xu, Hongbo [1 ,2 ]
Li, Shuhao [1 ,2 ]
Cheng, Zhenyu [1 ]
Qin, Rui [1 ]
Xie, Jiang [1 ,2 ]
Sun, Peishuai [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
来源
COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II | 2022年 / 461卷
关键词
Traffic classification; VPN; Encrypted traffic; Graph attention networks; Graph classification;
D O I
10.1007/978-3-031-24386-8_24
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Virtual Private Network (VPN) technology is now widely used in various scenarios such as telecommuting. The importance of VPN traffic identification for network security and management has increased significantly with the development of proxy technology. Unlike other tasks such as application classification, VPN traffic has only one flow problem. In addition, the development of encryption technology brings new challenges to VPN traffic identification. This paper proposes VT-GAT, a VPN traffic graph classification model based on Graph Attention Networks (GAT), to solve the above problems. Compared with existing VPN encrypted traffic classification techniques, VT-GAT solves the problem that previous techniques ignore the graph connectivity information contained in traffic. VT-GAT first constructs traffic behavior graphs by characterizing raw traffic data at packet and flow levels. Then it combines graph neural networks and attention mechanisms to extract behavioral features in the traffic graph data automatically. Extensive experimental results on the Datacon21 dataset show that VT-GAT can achieve over 99% in all classification metrics. Compared to existing machine learning and deep learning methods, VT-GAT improves F1-Score by about 3.02%-63.55%. In addition, VT-GAT maintains good robustness when the number of classification categories varies. These results demonstrate the usefulness of VT-GAT in the VPN traffic classification.
引用
收藏
页码:437 / 456
页数:20
相关论文
共 25 条
  • [1] [Anonymous], 2021, DataCon Community DataCon open Dataset-datacon2020-malicious code dataset direction open datasetDB/OL
  • [2] The Challenge of only One Flow Problem for Traffic Classification in Identity Obfuscation Environments
    Chen H.-Y.
    Lin T.-N.
    [J]. IEEE Access, 2021, 9 : 84110 - 84121
  • [3] Deri L, 2014, INT WIREL COMMUN, P617, DOI 10.1109/IWCMC.2014.6906427
  • [4] Draper-Gil Gerard, 2016, ICISSP 2016. 2nd International Conference on Information Systems Security and Privacy. Proceedings, P407
  • [5] A Survey of Payload-Based Traffic Classification Approaches
    Finsterbusch, Michael
    Richter, Chris
    Rocha, Eduardo
    Mueller, Jean-Alexander
    Haenssgen, Klaus
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2014, 16 (02) : 1135 - 1156
  • [6] Deep learning-based real-time VPN encrypted traffic identification methods
    Guo, Lulu
    Wu, Qianqiong
    Liu, Shengli
    Duan, Ming
    Li, Huijie
    Sun, Jianwen
    [J]. JOURNAL OF REAL-TIME IMAGE PROCESSING, 2020, 17 (01) : 103 - 114
  • [7] RETRACTED: CLD-Net: A Network Combining CNN and LSTM for Internet Encrypted Traffic Classification (Retracted Article)
    Hu, Xinyi
    Gu, Chunxiang
    Wei, Fushan
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [8] Characterization of Tor Traffic using Time based Features
    Lashkari, Arash Habibi
    Gil, Gerard Draper
    Mamun, Mohammad Saiful Islam
    Ghorbani, Ali A.
    [J]. ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 253 - 262
  • [9] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Lotfollahi, Mohammad
    Siavoshani, Mahdi Jafari
    Zade, Ramin Shirali Hossein
    Saberian, Mohammdsadegh
    [J]. SOFT COMPUTING, 2020, 24 (03) : 1999 - 2012
  • [10] Kipf TN, 2017, Arxiv, DOI arXiv:1609.02907