$Deep-Full-Range$ : A Deep Learning Based Network Encrypted Traffic Classification and Intrusion Detection Framework
Deep-Full-Range: фреймворк на основе глубокого обучения для классификации зашифрованного сетевого трафика и обнаружения вторжений
2019-01-01
SCID: 54.1/cjybutug
Discuss with AI
F1 scoredeep learningencrypted traffic classificationintrusion detectionraw traffic analysis
Figures from the paper
Abstract (AI)
With the rapid evolution of network traffic diversity, the understanding of network traffic has become more pivotal and more formidable. Previously, traffic classification and intrusion detection require a burdensome analyzing of various traffic features and attack-related characteristics by experts, and even, private information might be required. However, due to the outdated features labeling and privacy protocols, the existing approaches may not fit with the characteristics of the changing network environment anymore. In this paper, we present a light-weight framework with the aid of deep learning for encrypted traffic classification and intrusion detection, termed as deep-full-range (DFR). Thanks to deep learning, DFR is able to learn from raw traffic without manual intervention and private information. In such a framework, our proposed algorithms are compared with other state-of-the-art methods using two public datasets. The experimental results show that our framework not only can outperform the state-of-the-art methods by averaging 13.49% on encrypted traffic classification's F1 score and by averaging 12.15% on intrusion detection's F1 score but also require much lesser storage resource requirement.
Key Findings
1
DFR achieves these results while requiring substantially fewer storage resources than the compared approaches.
2
DFR improves intrusion-detection F1 score by an average of 12.15% compared with state-of-the-art methods.
3
DFR learns directly from raw network traffic without manual feature engineering or access to private information.
4
Deep-Full-Range (DFR) is a lightweight deep-learning framework for encrypted traffic classification and intrusion detection.
5
Evaluated on two public datasets, DFR outperforms state-of-the-art methods by an average of 13.49% in encrypted-traffic classification F1 score.
Research Object
encrypted network traffic and network intrusions
Research Subject
traffic classification and intrusion detection performance, including F1 score and storage-resource requirements
Publication Details
Publication Date
2019-01-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest