TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks

被引:2
|
作者
Wang, Leiqi [1 ,2 ]
Ma, Xiu [1 ,2 ]
Li, Ning [1 ]
Lv, Qiujian [1 ]
Wang, Yan [1 ,2 ]
Huang, Weiqing [1 ,2 ]
Chen, Haiyan [3 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Chinese Res Inst Environm Sci, Beijing, Peoples R China
关键词
Attack classification; Encrypted network traffic; Unseen attack; Attack graph; Graph neural networks;
D O I
10.1016/j.cose.2023.103466
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, most network traffic is encrypted, which protects user privacy but hides attack traces, further hindering identifying attacks to inspect traffic packages. Machine Learning (ML) methods are widely applied to attack classification on encrypted traffic owing to no need for manual analysis. However, existing studies only concentrate on basic statistical features and cannot obtain the crucial attack behaviors hiding in the encrypted traffic. Worse still, attackers constantly update attack vectors to evade detection, which means outdated features extracted from historical traffic fail to recognize unseen attacks. As a solution, we propose an attack classification approach, attack fingerprint based on graphs of time-window (TGPrint). We first filter normal traffic flows using ML models to eliminate the impact of useless, noisy data for attack classification and maintain suspicious traffic. Then, we create attack graphs to depict interaction behaviors of attack-victim hosts from suspicious traffic containing crucial attack behaviors. Besides, we divide a specific duration for each attack to precisely elaborate attack graphs, where temporal, statistical, and aggregate features are extracted to portray attack behaviors. Finally, we utilize Graph Neural Networks (GNNs) to mine and grasp the crucial behavior patterns from attack graphs to generate fingerprints and classify attacks, even unseen attacks. Extensive experiments are conducted on well-known datasets to verify our approach. It achieves a precision of 99% in attack classification on encrypted traffic, an average higher than other ML methods of 50%. Meanwhile, it classifies unseen attacks with an average accuracy of over 80% and has a strong robustness to false positives.
引用
收藏
页数:12
相关论文
共 50 条
  • [11] VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network
    Xu, Hongbo
    Li, Shuhao
    Cheng, Zhenyu
    Qin, Rui
    Xie, Jiang
    Sun, Peishuai
    COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II, 2022, 461 : 437 - 456
  • [12] Text Classification Based on Graph Convolution Neural Network and Attention Mechanism
    Zhai, Sheping
    Zhang, Wenqing
    Cheng, Dabao
    Bai, Xiaoxia
    ACM International Conference Proceeding Series, 2022, : 137 - 142
  • [13] Graph convolution networks based on adaptive spatiotemporal attention for traffic flow forecasting
    Xiao, Hongbo
    Zou, Beiji
    Xiao, Jianhua
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [14] Encrypted Network Traffic Classification with Higher Order Graph Neural Network
    Okonkwo, Zulu
    Foo, Ernest
    Hou, Zhe
    Li, Qinyi
    Jadidi, Zahra
    INFORMATION SECURITY AND PRIVACY, ACISP 2023, 2023, 13915 : 630 - 650
  • [15] Decomposition with feature attention and graph convolution network for traffic forecasting
    Liu, Yumang
    Wu, Xiao
    Tang, Yi
    Li, Xu
    Sun, Dihua
    Zheng, Linjiang
    KNOWLEDGE-BASED SYSTEMS, 2024, 300
  • [16] A Mobile Application-Classifying Method Based on a Graph Attention Network from Encrypted Network Traffic
    Xu, Guoliang
    Xu, Ming
    Chen, Yunzhi
    Zhao, Jiaqi
    ELECTRONICS, 2023, 12 (10)
  • [17] An Encrypted Traffic Classification Framework Based on Higher-Interaction-Graph Neural Network
    Hu, Zitong
    Qu, Bo
    Li, Xiang
    Li, Cong
    INFORMATION SECURITY AND PRIVACY, PT III, ACISP 2024, 2024, 14897 : 383 - 403
  • [18] SAFSN: A Self-Attention Based Neural Network for Encrypted Mobile Traffic Classification
    Zhang, Chengyuan
    An, Changqing
    Wang, Jessie Hui
    Zhao, Ziyi
    Yu, Tao
    Wang, Jilong
    IEEE CONGRESS ON CYBERMATICS / 2021 IEEE INTERNATIONAL CONFERENCES ON INTERNET OF THINGS (ITHINGS) / IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) / IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) / IEEE SMART DATA (SMARTDATA), 2021, : 330 - 337
  • [19] Spatio-Temporal Attention-based Graph Convolution Networks for Traffic Prediction
    Chongqing University, College of Computer Science, Chongqing, China
    Conf. Proc. IEEE Int. Conf. Syst. Man Cybern., 2022, (642-649): : 642 - 649
  • [20] Attention Mechanism Based Spatial-Temporal Graph Convolution Network for Traffic Prediction
    Xiao, Wenjuan
    Wang, Xiaoming
    Journal of Computers (Taiwan), 2024, 35 (04) : 93 - 108