Deep Learning for Encrypted Traffic Classification and Unknown Data Detection
Глубокое обучение для классификации зашифрованного трафика и обнаружения неизвестных данных
2022-10-09
SCID: 54.1/ekgu724x
Discuss with AI
deep neural networkencrypted traffic classificationin-app activity detectiontime window-based traffic segmentationunknown data detection
Figures from the paper
Abstract (AI)
Despite the widespread use of encryption techniques to provide confidentiality over Internet communications, mobile device users are still susceptible to privacy and security risks. In this paper, a novel Deep Neural Network (DNN) based on a user activity detection framework is proposed to identify fine-grained user activities performed on mobile applications (known as in-app activities) from a sniffed encrypted Internet traffic stream. One of the challenges is that there are countless applications, and it is practically impossible to collect and train a DNN model using all possible data from them. Therefore, in this work, we exploit the probability distribution of a DNN output layer to filter the data from applications that are not considered during the model training (i.e., unknown data). The proposed framework uses a time window-based approach to divide the traffic flow of activity into segments so that in-app activities can be identified just by observing only a fraction of the activity-related traffic. Our tests have shown that the DNN-based framework has demonstrated an accuracy of 90% or above in identifying previously trained in-app activities and an average accuracy of 79% in identifying previously untrained in-app activity traffic as unknown data when this framework is employed.
Key Findings
1
A deep neural network identifies fine-grained in-app user activities from sniffed encrypted Internet traffic without decrypting communications.
2
DNN output-layer probability distributions are exploited to filter traffic from applications and activities absent from model training as unknown data.
3
The approach addresses the impracticality of collecting training data for the countless applications used on mobile devices.
4
The framework achieves at least 90% accuracy for previously trained in-app activities and averages 79% accuracy when detecting previously untrained activity traffic as unknown.
5
The framework uses time-window segmentation to recognize activities while observing only a fraction of their activity-related traffic.
Research Object
Encrypted Internet traffic from mobile applications, including trained and previously unseen in-app activities
Research Subject
Fine-grained identification of in-app user activities and detection of unknown application data from segmented encrypted traffic using DNN output probabilities
Publication Details
Publication Date
2022-10-09
Journal
Publisher
ISSN
Cited by
32
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai5
Data Structures for Statistical Computing in Python2010
End-to-end encrypted traffic classification with one-dimensional convolution neural networks2017
Deep Learning for Encrypted Traffic Classification: An Overview2019
FS-Net: A Flow Sequence Network For Encrypted Traffic Classification2019
Mobile Encrypted Traffic Classification Using Deep Learning2018