TLS Encrypted Application Classification Using Machine Learning with Flow Feature Engineering

Классификация приложений зашифрованного TLS-трафика с использованием машинного обучения и инженерии фич потока
Yan Luo, Onur Barut, Rebecca Zhu, Tong Zhang
2020-11-27

Synthetic Minority Over-Sampling Technique (SMOTE)TLS Encrypted Application Classificationfeature selectionflow feature engineeringmachine learning
Network traffic classification has become increasingly important as the number of devices connected to the Internet is rapidly growing. Proportionally, the amount of encrypted traffic is also increasing, making payload based classification methods obsolete. Consequently, machine learning approaches have become crucial when user privacy is concerned. For this purpose, we propose an accurate, fast, and privacy preserved encrypted traffic classification approach with engineered flow feature extraction and appropriate feature selection. The proposed scheme achieves a 0.92899 macro-average F1 score and a 0.88313 macro-averaged mAP score for the encrypted traffic classification of Audio, Email, Chat, and Video classes derived from the non-vpn2016 dataset. Further experiments on the mixed non-encrypted and encrypted flow dataset with a data augmentation method called Synthetic Minority Over-Sampling Technique are conducted and the results are discussed for TLS-encrypted and mixed flows.
1
Experiments included mixed non-encrypted and encrypted flow datasets augmented with SMOTE (Synthetic Minority Over-Sampling Technique) and results were analyzed for TLS-encrypted and mixed flows.
2
Proposed a privacy-preserving encrypted traffic classification method using engineered flow features and feature selection.
3
The method achieved a macro-averaged mAP score of 0.88313 on the same encrypted traffic classification task.
4
The proposed scheme achieved a macro-average F1 score of 0.92899 on TLS-encrypted traffic classification for Audio, Email, Chat, and Video classes from the non-vpn2016 dataset.

TLS-encrypted network application traffic flows (Audio, Email, Chat, Video) derived from the non-vpn2016 dataset

Accuracy and performance of machine-learning-based encrypted traffic classification using engineered flow features, feature selection, and data augmentation (SMOTE), measured by macro-average F1 and mAP

Publication Details
Publication Date
2020-11-27
Journal
Publisher
ISSN
Cited by
16
Access Type
Author Information
Authors
Yan Luo
Onur Barut
Rebecca Zhu
Tong Zhang
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat →
Make a presentation
100%