A Novel Multimodal Deep Learning Framework for Encrypted Traffic Classification
Новая мультимодальная глубокая обучающая архитектура для классификации зашифрованного трафика
2022-11-04
SCID: 54.1/jfswsse9
Discuss with AI
PEANencrypted traffic classificationmultimodal deep learningself-attentionunsupervised pre-training
Figures from the paper
Abstract (AI)
Traffic classification is essential for cybersecurity maintenance and network management, and has been widely used in QoS (Quality of Service) guarantees, intrusion detection, and other tasks. Recently, with the emergence of SSL/TLS encryption protocols in the modern Internet environment, the traditional payload-based classification methods are no longer effective. Some researchers have used machine learning methods to model the flow features of encrypted traffics (e.g. message type, length sequence, statistical features, etc.), and achieved good results in some cases. However, these high-level hand-designed features cannot be used for more fine-grained operations and may lead to the loss of important information, thus affecting the classification accuracy. To overcome this limitation, in this paper, we designed a novel multimodal deep learning framework for encrypted traffic classification called PEAN. PEAN uses the raw bytes and length sequence as the input, and uses the self-attention mechanism to learn the deep relationship among network packets in a biflow. Furthermore, unsupervised pre-training was introduced to enhance PEAN’s ability to characterize network packets. Experiments on a real trace set captured in a large data center demonstrate the effectiveness of PEAN, which achieves better results than the state-of-the-art methods.
Key Findings
1
On a real trace set from a large data center, PEAN outperforms state-of-the-art methods in encrypted traffic classification.
2
PEAN employs a self-attention mechanism to learn deep relationships among network packets within a biflow.
3
PEAN is a novel multimodal deep learning framework for encrypted traffic classification that inputs raw bytes and length sequences.
4
Unsupervised pre-training is incorporated to enhance PEAN’s ability to characterize network packets.
5
Using raw bytes and length sequences avoids loss of information from high-level hand-designed features, improving fine-grained classification capability.
Research Object
Encrypted network traffic flows (biflows) represented by raw bytes and packet length sequences
Research Subject
Multimodal deep learning-based classification of encrypted traffic using self-attention to learn inter-packet relationships and unsupervised pre-training to improve packet characterization
Publication Details
Publication Date
2022-11-04
Journal
Publisher
ISSN
Cited by
124
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai8
Exploiting Generative AI to Scale up Intelligent Tutoring Systems2023
Deep Learning for Encrypted Traffic Classification: An Overview2019
FS-Net: A Flow Sequence Network For Encrypted Traffic Classification2019
AI-Assisted Pipeline for Dynamic Generation of Trustworthy Health Supplement Content at Scale2018
MaMPF: Encrypted Traffic Classification Based on Multi-Attribute Markov Probability Fingerprints2018
End-to-end encrypted traffic classification with one-dimensional convolution neural networks2017
A survey of methods for encrypted traffic classification and analysis2015
Learning Phrase Representations using RNN Encoder–Decoder for Statistical Machine Translation2014