Return
IP packet-level encrypted traffic classification using machine learning with a light weight feature engineering method
DOI:10.1016/j.jisa.2023.103519.png)
Abstract
En 中文
As the importance of personal data privacy increases, traffic encryption has become an important topic in network communication. In the field of network security and management, the development of encrypted traffic classification technology has drawn attention to deep learning methods. For raw encrypted traffic, deep learning models can realize end-to-end classification with high accuracy. However, deep learning methods do not explain which part of the encrypted traffic is critical to classification, and that will limit their application in some cyber security scenarios that demand high interpretability. The approach proposed in this paper features a novel feature engineering method named BITizationto determine the encoding method of features and a sliding window technique to explore which bytes contribute the most to the classification. The accuracy of classical machine learning methods in encrypted traffic is improved by at least 14.1% through the proposed feature engineering approach. In the experiments, the enhanced methods achieve a 98.6% average accuracy and a 98.5% average F1-score on the ISCX-VPN-Service, Cross-Platform-IOS, Cross-Platform-Android, and USTC-TFC2016 datasets, from which we believe a state-of-the-art performance is achieved.
Keywords:
Encrypted traffic classification
IP packet
Feature engineering
Machine learning
Cyber security
Journal
IF:
3.7
Papers:
2.0K
Citations:
4.9K
Organization
Cited Papers
A new multi-label dataset for Web attacks CAPEC classification using machine learning techniques
COMPUTERS & SECURITY
IF5.4
Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures
SENSORS
IF3.5

