Encrypted Network Traffic Classification Using Deep and Parallel Network-in-Network Models

Классификация зашифрованного сетевого трафика с использованием глубоких и параллельных моделей «сеть в сети»
Zhiyong Bu, Bin Zhou, Pengyu Cheng, Kecheng Zhang, Zhen-Hua Ling
2020-01-01

F1 scoreISCX VPN-nonVPN datasetencrypted network traffic classificationnetwork-in-network modelsparallel decision strategy
Network traffic classification aims to recognize different application or traffic types by analyzing received data packets. This paper presents a neural network model with deep and parallel network-in-network (NIN) structures for classifying encrypted network traffic. Comparing with standard convolutional neural networks (CNN), NIN adopts a micro network after each convolution layer to enhance local modeling. Besides, NIN utilizes a global average pooling instead of traditional fully connected layers before final classification, which reduces the number of model parameters significantly. In our proposed method, deep NIN models with multiple MLP convolutional layers are built to map fixed-length packet vectors towards application or traffic labels. Furthermore, a parallel decision strategy of building two sub-networks to process packet header and packet body separately is designed considering that they may carry different kinds of clues for classification. The results of our experiments on the “ISCX VPN-nonVPN” encrypted traffic dataset show that NIN models can achieve a better balance between classification accuracy and model complexity than conventional CNNs. The parallel decision strategy can further improve the accuracy of using single NIN model for encrypted network traffic classification. Finally, the test set F1 scores of 0.983 and 0.985 are achieved for traffic characterization and application identification respectively.
1
A deep Network-in-Network (NIN) model classifies encrypted network traffic by mapping fixed-length packet vectors to application or traffic labels.
2
A parallel architecture processes packet headers and bodies separately, exploiting their different classification clues and improving accuracy over a single NIN model.
3
NIN’s micro-networks after convolution layers improve local modeling, while global average pooling substantially reduces parameters compared with fully connected layers.
4
On the ISCX VPN-nonVPN dataset, NIN models provide a better balance between classification accuracy and model complexity than conventional CNNs.
5
The proposed approach achieves test-set F1 scores of 0.983 for traffic characterization and 0.985 for application identification.

encrypted network traffic, represented by fixed-length packet vectors and separated packet headers and bodies

application and traffic-type classification performance, including the accuracy–model-complexity trade-off and the contribution of separate header/body processing

Publication Details
Publication Date
2020-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Zhiyong Bu
Bin Zhou
Pengyu Cheng
Kecheng Zhang
Zhen-Hua Ling
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%