Encrypted Network Traffic Fine-Grained Identification Mechanism Based on Data Fingerprint and Multi-Classifier Decision

Механизм тонко‑гранулярной идентификации зашифрованного сетевого трафика на основе отпечатков данных и решения мультиклассификатора
Yaojiang Wu, Yufan Zhang, Bokun Liu, Xiaowei Chen, Aodi Liu
2024-05-24

ISCX VPN-nonVPN datasetdata fingerprint extractionencrypted network traffic fine-grained identificationmulti-classifier decision (SVM, KNN)voting ensemble for encrypted traffic classification
Addressing the issues of high computational overhead, prolonged model training time, and coarse granularity in existing encrypted network traffic perception technologies, this paper proposes a fine-grained identification mechanism for encrypted network traffic based on data fingerprints and multi-classifier decision-making. By utilizing rules for extracting data fingerprints from encrypted network traffic, this mechanism achieves feature extraction of encrypted network traffic data, allowing for precise characterization of encrypted network flow data at the transport layer. Subsequently, a fine-grained analysis method for encrypted network traffic based on multi-classifier decision-making was designed. By integrating several small model encryption traffic classifier algorithms such as SVM and KNN algorithms, and using the voting decision of multiple classifiers, this method conducts a fine-grained analysis of encrypted network traffic. It identifies and analyzes the encryption status of network flows, the application types of encrypted network flows, and the content types of encrypted network flows, providing robust decision support for subsequent malicious network traffic perception. The method achieved commendable experimental results in the authoritative dataset ISCX VPN-nonVPN, verifying the effectiveness of this mechanism.
1
Achieves commendable experimental results on the ISCX VPN-nonVPN dataset, validating the effectiveness of the proposed mechanism.
2
Designs a multi-classifier voting scheme combining small models (e.g., SVM and KNN) for fine-grained analysis of encryption status, application type, and content type.
3
Introduces rules to extract data fingerprints from encrypted traffic, enabling precise feature extraction at the transport layer.
4
Method provides robust decision support for downstream malicious network traffic perception by jointly identifying encryption state, application, and content types.
5
Proposes a fine-grained identification mechanism for encrypted network traffic using data fingerprints and multi-classifier decision-making.

Encrypted network traffic flows at the transport layer

Fine-grained identification and characterization of encrypted network traffic using data-fingerprint feature extraction and multi-classifier (voting) decision-making to detect encryption status, application types, and content types

Publication Details
Publication Date
2024-05-24
Journal
Publisher
ISSN
Cited by
1
Access Type
Author Information
Authors
Yaojiang Wu
Yufan Zhang
Bokun Liu
Xiaowei Chen
Aodi Liu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%