arrow
返回

Encrypted network traffic classification based on machine learning

delete2024-02-01
delete6
delete
OA
AI
R
Reham Taher El-Maghraby *
N
Nada M. Abdel Aziem
S
Sobh, Mohammed A.
A
Ayman M. Bahaa-Eldin
DOI:10.1016/j.asej.2023.102361delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Encrypted traffic is an essential part of maintaining the security and privacy of data transmission. It plays an important role in keeping our networks secure by preventing attackers from intercepting confidential information, which they may access without authorization; However, its effectiveness relies heavily on accurate classification techniques being applied correctly, so we can differentiate between legitimate users' activities versus those attempting malicious activity within the networks' boundaries. Encrypted network traffic is becoming increasingly common in modern communication systems, presenting a challenge for effective network management and security. To address this challenge, machine learning models have been employed to classify encrypted traffic but with limited success due to the lack of clear visibility into packet contents and an inability to inspect their content. For the sake of tackling this issue, more effective research has begun on developing machine learning models for classifying encrypted payloads without relying on inspecting their contents directly. This research will investigate how features like packet length, time stamps or transport layer security (TLS) and encrypted payload information can be used as input features when attempting classification tasks, instead of analyzing unencrypted content directly from packets themselves which would otherwise be impossible given the current technology constraints. The evaluation process will focus on assessing different model architectures, as well as feature selection techniques that yield improved results over the existing approaches. In this paper, we proposed three approaches to identify encrypted traffic and classify different applications such as browsing, VOIP, file transfer and video streaming. The first two techniques consist of two stages: the first stage is either a neural network or a bi-directional LSTM, and the second stage is a selection of different classification techniques, namely Random Forest, Support vector machine, Linear regression, and K-nearest neighbor. The final result is achieved using an ensemble voting technique. As for the third technique, the network packets are grouped together by Source IP, destination IP and session time before feeding them into three different combinations of LSTM networks; either coupled with convolution 1D or 2D layers, or without. Like the first two techniques, the final result is achieved by means of ensemble voting. Through extensive comparison between the three approaches, The first approach yielded the highest accuracy. However, the performance of the second and third techniques in terms of time complexity was superior. The achieved accuracies were 96.8%, 95.2% and 96.5% for the proposed techniques, respectively.(c) 2023 THE AUTHORS. Published by Elsevier BV on behalf of Faculty of Engineering, Ain Shams UniversityThis is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Ain Shams Engineering Journal 封面图
Ain Shams Engineering Journal
IF:
5.9
论文数:
3.4K
被引数:
1.2W

机构

E
egyptian knowledge bank (ekb)
学者数:
11.6W
论文数: 9.3W
被引数: 84
A
Ain Shams University
学者数:
6.4K
论文数: 5.5K
被引数: 8.9K
引用论文

引用论文

err分享
err收藏
err分享
err收藏
Effects of lesions of the locus coeruleus on aggressive behavior in rats
err1978-11-01
err0
PREAI
errWojciech Kostowski; Andrzej Czlonkowski; Maria Jerlicz; Andrzej Bidzinski; Miroslawa Hauptmann
err分享
err收藏
Elective stenting, platelet serotonin and thrombotic events
err2009-07-07
err0
PREAI
errFuad Lechin; Bertha van der Dijs; Beatriz Orozco; Simon Rodríguez; Scarlet Baez
err分享
err收藏
err分享
err收藏
Deep packet: a novel approach for encrypted traffic classification using deep learning深度包: 一种基于深度学习的加密流量分类新方法
err2019-05-13
err597
errOAAI
errLotfollahi, Mohammad; Siavoshani, Mahdi Jafari; Zade, Ramin Shirali Hossein; Saberian, Mohammdsadegh
err分享
err收藏
没有更多内容