Semi-Supervised Encrypted Traffic Classification With Deep Convolutional Generative Adversarial Networks
Полуконтролируемая классификация зашифрованного трафика с использованием глубоких сверточных генеративно-состязательных сетей
2019-12-25
SCID: 54.1/pck32r43
Discuss with AI
ISCX VPN-NonVPN datasetQUIC protocoldeep convolutional generative adversarial networksencrypted traffic classificationsemi-supervised learning
Figures from the paper
Abstract (AI)
Network traffic classification serves as a building block for important tasks such as security and quality of service management. The field has been studied for a long time, with many techniques such as classical machine learning and deep learning methods currently available. However, the emergence of stronger encryption protocols has led to the rise of new challenges. One of the challenges is capturing and labeling a large amount of encrypted traffic data especially for training deep learning classifiers, as current techniques rely on deep packet inspection tools (DPI) which perform poorly on encrypted traffic. In this paper, we propose a semi-supervised learning approach using Deep Convolutional Generative Adversarial Network (DCGAN). The basic idea is to utilize the samples generated by DCGAN generators as well as unlabeled data to improve the performance of a classifier trained on a few labeled samples. Thus, alleviating the difficulties associated with large dataset collecting and labeling. To demonstrate the efficacy of our approach, we evaluated our model using a self-collected dataset of the recently established QUIC protocol as well as publicly available ISCX VPN-NonVPN dataset. Our approach is able to achieve 89% and 78% accuracy with a very small number of labeled samples (just 10% of the dataset) on both QUIC and ISCX VPN-NonVPN datasets respectively.
Key Findings
1
On a self-collected QUIC dataset, the method achieves 89% accuracy using labeled data comprising only 10% of the dataset.
2
On the publicly available ISCX VPN-NonVPN dataset, the method achieves 78% accuracy with only 10% labeled samples.
3
The approach addresses the difficulty of collecting and labeling encrypted traffic, where deep packet inspection performs poorly because payloads are encrypted.
4
The evaluation indicates that DCGAN-generated samples and unlabeled traffic can improve classification when labeled encrypted-traffic data are scarce.
5
The paper introduces a semi-supervised encrypted-traffic classifier that combines unlabeled data with DCGAN-generated samples and a small labeled set.
Research Object
Encrypted network traffic, including QUIC and VPN/NonVPN traffic
Research Subject
Semi-supervised classification performance using DCGAN-generated samples and unlabeled data with limited labeled samples
Publication Details
Publication Date
2019-12-25
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest