MaMPF: Encrypted Traffic Classification Based on Multi-Attribute Markov Probability Fingerprints

MaMPF: Классификация шифрованного трафика на основе многопризнаковых марковских вероятностных отпечатков
Gang Xiong, Gaopeng Gou, Chang Liu, Longtao He, Zigang Cao, Siu‐Ming Yiu
2018-06-01

Markov modelsMulti-attribute Markov Probability FingerprintsSSL/TLS encrypted trafficencrypted traffic classificationlength block sequence
With the explosion of network applications, network anomaly detection and security management face a big challenge, of which the first and a fundamental step is traffic classification. However, for the sake of user privacy, encrypted communication protocols, e.g. the SSL/TLS protocol, are extensively used, which results in the ineffectiveness of traditional rule-based classification methods. Existing methods cannot have a satisfactory accuracy of encrypted traffic classification because of insufficient distinguishable characteristics. In this paper, we propose the Multi-attribute Markov Probability Fingerprints (MaMPF), for encrypted traffic classification. The key idea behind MaMPF is to consider multi-attributes, which includes a critical feature, namely “length block sequence” that captures the time-series packet lengths effectively using power-law distributions and relative occurrence probabilities of all considered applications. Based on the message type and length block sequences, Markov models are trained and the probabilities of all the applications are concatenated as the fingerprints for classification. MaMPF achieves 96.4% TPR and 0.2% FPR performance on a real-world dataset from campus network (including 950,000+ encrypted traffic flows and covering 18 applications), and outperforms the state-of-the-art methods.
1
Introduces a critical feature called "length block sequence" that models time-series packet lengths using power-law distributions and relative occurrence probabilities.
2
MaMPF outperforms state-of-the-art methods for encrypted traffic classification on the evaluated dataset.
3
On a real-world campus dataset (950,000+ encrypted flows, 18 applications), MaMPF achieves 96.4% true positive rate (TPR) and 0.2% false positive rate (FPR).
4
Proposes MaMPF, a Multi-attribute Markov Probability Fingerprints method for encrypted traffic classification using multi-attributes including message type and length block sequences.
5
Trains Markov models on message type and length block sequences and concatenates per-application probabilities as fingerprints for classification.

Encrypted network traffic flows (SSL/TLS) from a campus network covering multiple applications

Classification of encrypted traffic using Multi-attribute Markov Probability Fingerprints (MaMPF), specifically modeling length block sequences and message types with Markov models to produce probabilistic fingerprints for application identification

Publication Details
Publication Date
2018-06-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Gang Xiong
Gaopeng Gou
Chang Liu
Longtao He
Zigang Cao
Siu‐Ming Yiu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%