DISTILLER: Encrypted traffic classification via multimodal multitask deep learning

被引:134
作者
Aceto, Giuseppe [1 ]
Ciuonzo, Domenico [1 ]
Montieri, Antonio [2 ]
Pescape, Antonio [3 ]
机构
[1] Univ Napoli Federico II, Naples, Italy
[2] Univ Napoli Federico II, Dept Elect Engn & Informat Technol, Naples, Italy
[3] Univ Napoli Federico II, Comp Engn, Naples, Italy
关键词
Deep learning; Encrypted traffic; Traffic classification; Multimodal learning; Multitask learning; NETWORK; INTERNET;
D O I
10.1016/j.jnca.2021.102985
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic classification, i.e. the inference of applications and/or services from their network traffic, represents the workhorse for service management and the enabler for valuable profiling information. The growing trend toward encrypted protocols and the fast-evolving nature of network traffic are obsoleting the traffic-classification design solutions based on payload-inspection or machine learning. Conversely, deep learning is currently foreseen as a viable means to design traffic classifiers based on automatically-extracted features. These reflect the complex patterns distilled from the multifaceted (encrypted) traffic, that implicitly carries information in "multimodal" fashion, and can be also used in application scenarios with diversified network visibility for (simultaneously) tackling multiple classification tasks. To this end, in this paper a novel multimodal multitask deep learning approach for traffic classification is proposed, leading to the DISTILLER classifier. The latter is able to capitalize traffic-data heterogeneity (by learning both intra- and inter-modality dependencies), overcome performance limitations of existing (myopic) single-modal deep learning-based traffic classification proposals, and simultaneously solve different traffic categorization problems associated to different providers' desiderata. Based on a public dataset of encrypted traffic, we evaluate DISTILLER in a fair comparison with state-of-the-art deep learning architectures proposed for encrypted traffic classification (and based on single-modality philosophy). Results show the gains of our proposal over both multitask extensions of single-task baselines and native multitask architectures.
引用
收藏
页数:17
相关论文
共 43 条
[1]   Toward effective mobile encrypted traffic classification through deep learning [J].
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Montieri, Antonio ;
Pescape, Antonio .
NEUROCOMPUTING, 2020, 409 :306-315
[2]   MIMETIC: Mobile encrypted traffic classification using multimodal deep learning [J].
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Montieri, Antonio ;
Pescape, Antonio .
COMPUTER NETWORKS, 2019, 165
[3]   Mobile Encrypted Traffic Classification Using Deep Learning: Experimental Evaluation, Lessons Learned, and Challenges [J].
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Montieri, Antonio ;
Pescape, Antonio .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2019, 16 (02) :445-458
[4]   Multi-classification approaches for classifying mobile app traffic [J].
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Montieri, Antonio ;
Pescape, Antonio .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 103 :131-145
[5]  
[Anonymous], INT C LEARN REPR ICL
[6]  
[Anonymous], 2015, BlackHat USA
[7]  
Bernaille L., 2006, C FUTURE NETWORKING, P6
[8]  
Carela-Español V, 2010, LECT NOTES COMPUT SC, V6003, P141, DOI 10.1007/978-3-642-12365-8_11
[9]  
Chai Z., 2019, 9 USENIX WORKSH FREE
[10]   Issues and Future Directions in Traffic Classification [J].
Dainotti, Alberto ;
Pescape, Antonio ;
Claffy, Kimberly C. .
IEEE NETWORK, 2012, 26 (01) :35-40