Deep Packet: A Novel Approach For Encrypted Traffic Classification Using\n Deep Learning

Deep Packet: новый подход к классификации зашифрованного трафика с использованием глубокого обучения
Mohammad Nader Lotfollahi, Ramin Shirali Hossein Zade, Mahdi Jafari Siavoshani, Mohammdsadegh Saberian
2017-09-08

UNB ISCX VPN-nonVPN datasetconvolutional neural networkdeep learningencrypted traffic classificationstacked autoencoder
Internet traffic classification has become more important with rapid growth\nof current Internet network and online applications. There have been numerous\nstudies on this topic which have led to many different approaches. Most of\nthese approaches use predefined features extracted by an expert in order to\nclassify network traffic. In contrast, in this study, we propose a \\emph{deep\nlearning} based approach which integrates both feature extraction and\nclassification phases into one system. Our proposed scheme, called "Deep\nPacket," can handle both \\emph{traffic characterization} in which the network\ntraffic is categorized into major classes (\\eg, FTP and P2P) and application\nidentification in which end-user applications (\\eg, BitTorrent and Skype)\nidentification is desired. Contrary to most of the current methods, Deep Packet\ncan identify encrypted traffic and also distinguishes between VPN and non-VPN\nnetwork traffic. After an initial pre-processing phase on data, packets are fed\ninto Deep Packet framework that embeds stacked autoencoder and convolution\nneural network in order to classify network traffic. Deep packet with CNN as\nits classification model achieved recall of $0.98$ in application\nidentification task and $0.94$ in traffic categorization task. To the best of\nour knowledge, Deep Packet outperforms all of the proposed classification\nmethods on UNB ISCX VPN-nonVPN dataset.\n
1
Deep Packet integrates feature extraction and traffic classification in a single deep-learning framework, reducing reliance on expert-defined features.
2
Deep Packet supports both broad traffic categorization, such as FTP versus P2P, and application identification, such as BitTorrent versus Skype.
3
The framework combines stacked autoencoders with convolutional neural networks after packet preprocessing to classify network traffic.
4
The method identifies encrypted traffic and distinguishes VPN from non-VPN network traffic, capabilities uncommon in prior approaches.
5
Using CNN classification, Deep Packet achieves recall of 0.98 for application identification and 0.94 for traffic categorization, outperforming reported methods on the UNB ISCX VPN-nonVPN dataset.

encrypted Internet network traffic, including VPN and non-VPN traffic

traffic characterization and application identification through classification of major traffic classes and end-user applications

Publication Details
Publication Date
2017-09-08
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Mohammad Nader Lotfollahi
Ramin Shirali Hossein Zade
Mahdi Jafari Siavoshani
Mohammdsadegh Saberian
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%