Mobile Encrypted Traffic Classification Using Deep Learning: Experimental Evaluation, Lessons Learned, and Challenges
Классификация зашифрованного мобильного трафика с использованием глубокого обучения: экспериментальная оценка, извлеченные уроки и проблемы
2019-02-12
SCID: 54.1/7emq83hw
Discuss with AI
automatic feature extractiondeep learningencrypted protocolsmobile encrypted traffic classificationmobile traffic datasets
Figures from the paper
Abstract (AI)
The massive adoption of hand-held devices has led to the explosion of mobile traffic volumes traversing home and enterprise networks, as well as the Internet. Traffic classification (TC), i.e., the set of procedures for inferring (mobile) applications generating such traffic, has become nowadays the enabler for highly valuable profiling information (with certain privacy downsides), other than being the workhorse for service differentiation/blocking. Nonetheless, the design of accurate classifiers is exacerbated by the raising adoption of encrypted protocols (such as TLS), hindering the suitability of (effective) deep packet inspection approaches. Also, the fast-expanding set of apps and the moving-target nature of mobile traffic makes design solutions with usual machine learning, based on manually and expert-originated features, outdated and unable to keep the pace. For these reasons deep learning (DL) is here proposed, for the first time, as a viable strategy to design practical mobile traffic classifiers based on automatically extracted features, able to cope with encrypted traffic, and reflecting their complex traffic patterns. To this end, different state-of-the-art DL techniques from (standard) TC are here reproduced, dissected (highlighting critical choices), and set into a systematic framework for comparison, including also a performance evaluation workbench. The latter outcome, although declined in the mobile context, has the applicability appeal to the wider umbrella of encrypted TC tasks. Finally, the performance of these DL classifiers is critically investigated based on an exhaustive experimental validation (based on three mobile datasets of real human users' activity), highlighting the related pitfalls, design guidelines, and challenges.
Key Findings
1
Deep learning is presented as a practical strategy for classifying encrypted mobile traffic using automatically learned features rather than manually engineered features.
2
Encrypted protocols, rapidly expanding application ecosystems, and evolving mobile traffic patterns make deep-packet inspection and conventional feature-engineered machine learning increasingly inadequate.
3
Exhaustive experiments on three mobile datasets collected from real users critically assess classifier performance and reveal practical pitfalls, design guidelines, and unresolved challenges.
4
The proposed evaluation framework, although developed for mobile traffic, is applicable more broadly to encrypted traffic-classification tasks.
5
The study reproduces and systematically compares state-of-the-art deep-learning techniques for traffic classification, identifying critical design choices through a dedicated evaluation workbench.
Research Object
Mobile encrypted network traffic generated by mobile applications
Research Subject
deep-learning-based traffic classification performance, robustness, and design challenges for inferring the generating mobile applications
Publication Details
Publication Date
2019-02-12
Journal
Publisher
ISSN
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai3
Cited by7
Deep Learning for Network Traffic Monitoring and Analysis (NTMA): A Survey2021
Network traffic classification: Techniques, datasets, and challenges2022
FlowPic: A Generic Representation for Encrypted Traffic Classification and Applications Identification2021
Identification of Encrypted Traffic Using Advanced Mathematical Modeling and Computational Intelligence2022
Deep Learning-Based Signal-To-Noise Ratio Estimation Using Constellation Diagrams2020
Automatic Mobile App Identification From Encrypted Traffic With Hybrid Neural Networks2020
Encrypted Network Traffic Classification Using Deep and Parallel Network-in-Network Models2020