Return
EO-EPTC: End-to-End Original Traffic-Based Encrypted Proxy Traffic Classification Framework
DOI:10.1109/TIFS.2025.3646874.png)
Abstract
En 中文
Machine learning-based methods for encrypted traffic classification can be effectively applied to analyze encrypted proxy traffic generated by proxy protocols, which are intermediary protocols used to route network traffic through a remote server. Nonetheless, different encrypted proxy protocols generate distinct traffic patterns, even when they handle the same network behavior. To address these distribution differences, a straightforward approach is to collect datasets specific to each proxy protocol. However, typical proxy protocols repackage original traffic by encrypting it without payload padding or compression. This leads to a definite characteristic correlation between original and encrypted proxy traffic. We propose an End-to-end Original traffic-based Encrypted Proxy Traffic Classification framework (EO-EPTC) to bridge the distribution gap between original traffic and proxied traffic, enabling the classification of encrypted proxy traffic using a original traffic dataset. EO-EPTC conducts sequence feature alignment to reduce distribution bias and employs a Seq2Seq model to capture the underlying semantics of the proxy protocol, creating a sequence feature transformation model. We apply EO-EPTC to existing encrypted traffic classification models, training them on original traffic to classify proxied traffic. This achieves up to 99.70% accuracy on encrypted proxy traffic, comparable to models trained directly on proxied traffic.
Keywords:
Cryptography
Protocols
Servers
Accuracy
Training
Trojan horses
Payloads
Firewalls (computing)
Semantics
Costs
Encrypted proxy
traffic classification
distribution gap
dataset generation
Journal
IF:
8
Papers:
5.2K
Citations:
2.3W

