Deep Learning for Encrypted Traffic Classification and Unknown Data Detection

Глубокое обучение для классификации зашифрованного трафика и обнаружения неизвестных данных
Ahmet M. KONDOZ, Madushi H. Pathmaperuma, Yogachandran Rahulamathavan, Safak Dogan
2022-10-09

deep neural networkencrypted traffic classificationin-app activity detectiontime window-based traffic segmentationunknown data detection
Despite the widespread use of encryption techniques to provide confidentiality over Internet communications, mobile device users are still susceptible to privacy and security risks. In this paper, a novel Deep Neural Network (DNN) based on a user activity detection framework is proposed to identify fine-grained user activities performed on mobile applications (known as in-app activities) from a sniffed encrypted Internet traffic stream. One of the challenges is that there are countless applications, and it is practically impossible to collect and train a DNN model using all possible data from them. Therefore, in this work, we exploit the probability distribution of a DNN output layer to filter the data from applications that are not considered during the model training (i.e., unknown data). The proposed framework uses a time window-based approach to divide the traffic flow of activity into segments so that in-app activities can be identified just by observing only a fraction of the activity-related traffic. Our tests have shown that the DNN-based framework has demonstrated an accuracy of 90% or above in identifying previously trained in-app activities and an average accuracy of 79% in identifying previously untrained in-app activity traffic as unknown data when this framework is employed.
1
A deep neural network identifies fine-grained in-app user activities from sniffed encrypted Internet traffic without decrypting communications.
2
DNN output-layer probability distributions are exploited to filter traffic from applications and activities absent from model training as unknown data.
3
The approach addresses the impracticality of collecting training data for the countless applications used on mobile devices.
4
The framework achieves at least 90% accuracy for previously trained in-app activities and averages 79% accuracy when detecting previously untrained activity traffic as unknown.
5
The framework uses time-window segmentation to recognize activities while observing only a fraction of their activity-related traffic.

Encrypted Internet traffic from mobile applications, including trained and previously unseen in-app activities

Fine-grained identification of in-app user activities and detection of unknown application data from segmented encrypted traffic using DNN output probabilities

Publication Details
Publication Date
2022-10-09
Journal
Publisher
ISSN
Cited by
32
Access Type
Author Information
Authors
Ahmet M. KONDOZ
Madushi H. Pathmaperuma
Yogachandran Rahulamathavan
Safak Dogan
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat →
Make a presentation
100%