A Novel Multimodal Deep Learning Framework for Encrypted Traffic Classification

Новая мультимодальная глубокая обучающая архитектура для классификации зашифрованного трафика
Peng Lin, Kejiang Ye, Yishen Hu, Yanying Lin, Chengzhong Xu
2022-11-04

PEANencrypted traffic classificationmultimodal deep learningself-attentionunsupervised pre-training
Traffic classification is essential for cybersecurity maintenance and network management, and has been widely used in QoS (Quality of Service) guarantees, intrusion detection, and other tasks. Recently, with the emergence of SSL/TLS encryption protocols in the modern Internet environment, the traditional payload-based classification methods are no longer effective. Some researchers have used machine learning methods to model the flow features of encrypted traffics (e.g. message type, length sequence, statistical features, etc.), and achieved good results in some cases. However, these high-level hand-designed features cannot be used for more fine-grained operations and may lead to the loss of important information, thus affecting the classification accuracy. To overcome this limitation, in this paper, we designed a novel multimodal deep learning framework for encrypted traffic classification called PEAN. PEAN uses the raw bytes and length sequence as the input, and uses the self-attention mechanism to learn the deep relationship among network packets in a biflow. Furthermore, unsupervised pre-training was introduced to enhance PEAN’s ability to characterize network packets. Experiments on a real trace set captured in a large data center demonstrate the effectiveness of PEAN, which achieves better results than the state-of-the-art methods.
1
On a real trace set from a large data center, PEAN outperforms state-of-the-art methods in encrypted traffic classification.
2
PEAN employs a self-attention mechanism to learn deep relationships among network packets within a biflow.
3
PEAN is a novel multimodal deep learning framework for encrypted traffic classification that inputs raw bytes and length sequences.
4
Unsupervised pre-training is incorporated to enhance PEAN’s ability to characterize network packets.
5
Using raw bytes and length sequences avoids loss of information from high-level hand-designed features, improving fine-grained classification capability.

Encrypted network traffic flows (biflows) represented by raw bytes and packet length sequences

Multimodal deep learning-based classification of encrypted traffic using self-attention to learn inter-packet relationships and unsupervised pre-training to improve packet characterization

Publication Details
Publication Date
2022-11-04
Journal
Publisher
ISSN
Cited by
124
Access Type
Author Information
Authors
Peng Lin
Kejiang Ye
Yishen Hu
Yanying Lin
Chengzhong Xu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%