ATVITSC: A Novel Encrypted Traffic Classification Method Based on Deep Learning

ATVITSC: новый метод классификации зашифрованного трафика на основе глубокого обучения
Xiao Wang, Ya Liu, 博 名取, Fengyu Zhao
2024-01-01

Attention-based Vision Transformerbidirectional LSTMencrypted traffic classificationpacket vision transformer (PVT)spatiotemporal feature extraction
The increasing prevalence of encrypted communication on the modern internet has presented new challenges for traffic classification and network management. Traditional traffic classification methods cannot handle encrypted traffic effectively. Meanwhile, many existing methods either rely on hand-crafted features or fail to extract the underlying interaction patterns between data packets adequately. In this paper, we propose a novel encrypted traffic classification method called the Attention-based Vision Transformer and Spatiotemporal for Traffic Classification (ATVITSC). In the preprocessing stage, packet-level images within a session, generated from the payload of data packets, are combined into a session image to mitigate information confusion. In the classification stage, session images are first processed by the packet vision transformer (PVT) module, which employs the transformer encoder and multi-head self-attention mechanism, to capture the global features. In parallel, session images are also processed by the spatiotemporal feature extraction (STFE) module, where spatial features of packets are extracted by the convolution operation with the attention mechanism and temporal features between packets are then combined by the bidirectional Long Short-Term Memory (LSTM). The global and spatiotemporal features are fused in the feature fusion classification (FFC) module by a dynamic weighting mechanism and encrypted traffic is finally classified based on the fused features. Comprehensive experiments on various types of encrypted traffic, including virtual private network (VPN), onion router (Tor), malicious traffic, and mobile traffic, show that the ATVITSC successfully improves the macro-f1 scores to 97.88%, 98.79%, 99.67%, 94.90%, respectively. The results also reveal that the ATVITSC exhibits better classification performance and generalization ability than the state-of-the-art methods.
1
ATVITSC achieves macro-F1 scores of 97.88% (VPN), 98.79% (Tor), 99.67% (malicious traffic), and 94.90% (mobile traffic) on evaluated datasets.
2
ATVITSC outperforms state-of-the-art methods in classification performance and generalization ability according to experiments.
3
Feature Fusion Classification (FFC) module fuses global and spatiotemporal features using a dynamic weighting mechanism for final classification.
4
PVT module uses transformer encoder and multi-head self-attention to capture global features from session images.
5
Preprocessing merges packet-level images from a session into a single session image to reduce information confusion.
6
Proposed ATVITSC, combining an Attention-based Vision Transformer (PVT) and a Spatiotemporal Feature Extraction (STFE) module, for encrypted traffic classification.
7
STFE module extracts spatial features via convolution with attention and temporal packet relationships via bidirectional LSTM.

Encrypted network traffic sessions represented as packet-level session images for classification

Classification performance and feature-learning of encrypted traffic via the proposed ATVITSC model, specifically extraction/fusion of global (vision-transformer) and spatiotemporal (convolution + attention and bi‑LSTM) features and resulting macro-F1 improvements

Publication Details
Publication Date
2024-01-01
Journal
Publisher
ISSN
Cited by
67
Access Type
Author Information
Authors
Xiao Wang
Ya Liu
博 名取
Fengyu Zhao
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%