Deep Packet: A Novel Approach For Encrypted Traffic Classification Using\n Deep Learning
Deep Packet: новый подход к классификации зашифрованного трафика с использованием глубокого обучения
2017-09-08
SCID: 54.1/dct7wc7y
Discuss with AI
UNB ISCX VPN-nonVPN datasetconvolutional neural networkdeep learningencrypted traffic classificationstacked autoencoder
Figures from the paper
Abstract (AI)
Internet traffic classification has become more important with rapid growth\nof current Internet network and online applications. There have been numerous\nstudies on this topic which have led to many different approaches. Most of\nthese approaches use predefined features extracted by an expert in order to\nclassify network traffic. In contrast, in this study, we propose a \\emph{deep\nlearning} based approach which integrates both feature extraction and\nclassification phases into one system. Our proposed scheme, called "Deep\nPacket," can handle both \\emph{traffic characterization} in which the network\ntraffic is categorized into major classes (\\eg, FTP and P2P) and application\nidentification in which end-user applications (\\eg, BitTorrent and Skype)\nidentification is desired. Contrary to most of the current methods, Deep Packet\ncan identify encrypted traffic and also distinguishes between VPN and non-VPN\nnetwork traffic. After an initial pre-processing phase on data, packets are fed\ninto Deep Packet framework that embeds stacked autoencoder and convolution\nneural network in order to classify network traffic. Deep packet with CNN as\nits classification model achieved recall of $0.98$ in application\nidentification task and $0.94$ in traffic categorization task. To the best of\nour knowledge, Deep Packet outperforms all of the proposed classification\nmethods on UNB ISCX VPN-nonVPN dataset.\n
Key Findings
1
Deep Packet integrates feature extraction and traffic classification in a single deep-learning framework, reducing reliance on expert-defined features.
2
Deep Packet supports both broad traffic categorization, such as FTP versus P2P, and application identification, such as BitTorrent versus Skype.
3
The framework combines stacked autoencoders with convolutional neural networks after packet preprocessing to classify network traffic.
4
The method identifies encrypted traffic and distinguishes VPN from non-VPN network traffic, capabilities uncommon in prior approaches.
5
Using CNN classification, Deep Packet achieves recall of 0.98 for application identification and 0.94 for traffic categorization, outperforming reported methods on the UNB ISCX VPN-nonVPN dataset.
Research Object
encrypted Internet network traffic, including VPN and non-VPN traffic
Research Subject
traffic characterization and application identification through classification of major traffic classes and end-user applications
Publication Details
Publication Date
2017-09-08
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
Cited by3
Identification of Encrypted Traffic Using Advanced Mathematical Modeling and Computational Intelligence2022
On using eXtreme Gradient Boosting (XGBoost) Machine Learning algorithm for Home Network Traffic Classification2019
Mobile Encrypted Traffic Classification Using Deep Learning: Experimental Evaluation, Lessons Learned, and Challenges2019