FlowPic: A Generic Representation for Encrypted Traffic Classification and Applications Identification

FlowPic: универсальное представление для классификации зашифрованного трафика и идентификации приложений
Tal Shapira, Yuval Shavitt
2021-04-06

FlowPicVPN and Tor trafficapplication identificationconvolutional neural networksencrypted traffic classification
Identifying the type of a network flow or a specific application has many advantages, such as, traffic engineering, or to detect and prevent application or application types that violate the organization’s security policy. The use of encryption, such as VPN, makes such identification challenging. Current solutions rely mostly on handcrafted features and then apply supervised learning techniques for the classification. We introduce a novel approach for encrypted Internet traffic classification and application identification by transforming basic flow data into an intuitive picture, aFlowPic, and then using known image classification deep learning techniques, CNNs, to identify the flow category (browsing, chat, video, etc.) and the application in use. We show that our approach can classify traffic with high accuracy, both for a specific application, or a flow category, even for VPN and Tor traffic. Our classifier can even identify with high success new applications that were not part of the training phase for a category, thus, new versions or applications can be categorized without additional training.
1
FlowPic achieves high classification accuracy for encrypted traffic, including VPN and Tor flows.
2
FlowPic transforms basic encrypted-flow data into an image-like representation, aFlowPic, enabling CNN-based traffic classification.
3
The approach identifies both broad flow categories, such as browsing, chat, and video, and specific applications.
4
The classifier can successfully categorize previously unseen applications within a trained category without additional training.
5
The method offers an alternative to handcrafted-feature pipelines for encrypted Internet traffic classification and application identification.

Encrypted Internet network flows, including VPN and Tor traffic, and the applications or flow categories generating them

Classification and identification of flow categories and applications from basic encrypted-flow data, including recognition of previously unseen applications

Publication Details
Publication Date
2021-04-06
Journal
Publisher
ISSN
Cited by
222
Access Type
Author Information
Authors
Tal Shapira
Yuval Shavitt
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat →
Make a presentation
100%