MaMPF: Encrypted Traffic Classification Based on Multi-Attribute Markov Probability Fingerprints
MaMPF: Классификация шифрованного трафика на основе многопризнаковых марковских вероятностных отпечатков
2018-06-01
SCID: 54.1/8hv7wn4j
Discuss with AI
Markov modelsMulti-attribute Markov Probability FingerprintsSSL/TLS encrypted trafficencrypted traffic classificationlength block sequence
Figures from the paper
Abstract (AI)
With the explosion of network applications, network anomaly detection and security management face a big challenge, of which the first and a fundamental step is traffic classification. However, for the sake of user privacy, encrypted communication protocols, e.g. the SSL/TLS protocol, are extensively used, which results in the ineffectiveness of traditional rule-based classification methods. Existing methods cannot have a satisfactory accuracy of encrypted traffic classification because of insufficient distinguishable characteristics. In this paper, we propose the Multi-attribute Markov Probability Fingerprints (MaMPF), for encrypted traffic classification. The key idea behind MaMPF is to consider multi-attributes, which includes a critical feature, namely “length block sequence” that captures the time-series packet lengths effectively using power-law distributions and relative occurrence probabilities of all considered applications. Based on the message type and length block sequences, Markov models are trained and the probabilities of all the applications are concatenated as the fingerprints for classification. MaMPF achieves 96.4% TPR and 0.2% FPR performance on a real-world dataset from campus network (including 950,000+ encrypted traffic flows and covering 18 applications), and outperforms the state-of-the-art methods.
Key Findings
1
Introduces a critical feature called "length block sequence" that models time-series packet lengths using power-law distributions and relative occurrence probabilities.
2
MaMPF outperforms state-of-the-art methods for encrypted traffic classification on the evaluated dataset.
3
On a real-world campus dataset (950,000+ encrypted flows, 18 applications), MaMPF achieves 96.4% true positive rate (TPR) and 0.2% false positive rate (FPR).
4
Proposes MaMPF, a Multi-attribute Markov Probability Fingerprints method for encrypted traffic classification using multi-attributes including message type and length block sequences.
5
Trains Markov models on message type and length block sequences and concatenates per-application probabilities as fingerprints for classification.
Research Object
Encrypted network traffic flows (SSL/TLS) from a campus network covering multiple applications
Research Subject
Classification of encrypted traffic using Multi-attribute Markov Probability Fingerprints (MaMPF), specifically modeling length block sequences and message types with Markov models to produce probabilistic fingerprints for application identification
Publication Details
Publication Date
2018-06-01
Journal
Publisher
ISSN
Access Type
Author Information
Download PDF
Subscribe to digest