Flow-Based Encrypted Network Traffic Classification With Graph Neural Networks

被引:13
|
作者
Huoh, Ting-Li [1 ]
Luo, Yan [1 ]
Li, Peilong [2 ]
Zhang, Tong [3 ]
机构
[1] Univ Massachusetts Lowell, Dept Elect & Comp Engn, Lowell, MA 01854 USA
[2] Elizabethtown Coll, Dept Comp Sci, Elizabethtown, PA 17022 USA
[3] Intel Corp, Network Platforms Grp, Santa Clara 95054, CA USA
关键词
Encrypted network traffic analysis; network traffic classification; deep learning; graph neural networks; multimodal deep learning;
D O I
10.1109/TNSM.2022.3227500
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Classifying encrypted traffic from emerging applications is important but challenging as many conventional traffic classification approaches are ineffective, thus calling for novel methods for identifying encrypted network flows. Recent machine learning and deep learning-based approaches are severely limited by their feature selection and inherent neural network architecture. More importantly, they overlook the opportunity to capture latent information in the temporal dimension of packets. As network data by nature are of non-Euclidean distance space and carry abundant chronological and temporal relations, we are inspired to utilize geometric deep learning that simultaneously takes into account packet raw bytes, metadata and packet relations for classifying encrypted network traffic. Our proposed graph neural network (GNN) model outperforms the two reference methods, convolutional neural networks (CNN) and recurrent neural networks (RNN) quantitatively as indicated by three metrics: sensitivity, precision and F1 score.
引用
收藏
页码:1224 / 1237
页数:14
相关论文
共 50 条
  • [1] Learning to Classify: A Flow-Based Relation Network for Encrypted Traffic Classification
    Zheng, Wenbo
    Gou, Chao
    Yan, Lan
    Mo, Shaocong
    [J]. WEB CONFERENCE 2020: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2020), 2020, : 13 - 22
  • [2] WFF-EGNN: Encrypted Traffic Classification Based on Weaved Flow Fragment via Ensemble Graph Neural Networks
    School of Cyber Science and Engineering, Southeast University, Nanjing
    210096, China
    不详
    211189, China
    不详
    211111, China
    [J]. IEEE. Trans. Mach. Learn. Commun. Netw., 2023, (389-411):
  • [3] TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks
    Wang, Leiqi
    Ma, Xiu
    Li, Ning
    Lv, Qiujian
    Wang, Yan
    Huang, Weiqing
    Chen, Haiyan
    [J]. COMPUTERS & SECURITY, 2023, 135
  • [4] Encrypted Traffic Classification Based on Text Convolution Neural Networks
    Song, Mingze
    Ran, Jing
    Li, Shulan
    [J]. PROCEEDINGS OF 2019 IEEE 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2019), 2019, : 432 - 436
  • [5] MAppGraph: Mobile-App Classification on Encrypted Network Traffic using Deep Graph Convolution Neural Networks
    Thai-Dien Pham
    Thien-Lac Ho
    Tram Truong-Huu
    Tien-Dung Cao
    Hong-Linh Truong
    [J]. 37TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2021, 2021, : 1025 - 1038
  • [6] Encrypted Traffic Classification Using Graph Convolutional Networks
    Mo, Shuang
    Wang, Yifei
    Xiao, Ding
    Wu, Wenrui
    Fan, Shaohua
    Shi, Chuan
    [J]. ADVANCED DATA MINING AND APPLICATIONS, 2020, 12447 : 207 - 219
  • [7] Research And Improvement of Encrypted Traffic Classification Based on Convolutional Neural Network
    Zhou, Yansen
    Cui, Jianquan
    [J]. 2020 IEEE 8TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), 2020, : 150 - 154
  • [8] VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network
    Xu, Hongbo
    Li, Shuhao
    Cheng, Zhenyu
    Qin, Rui
    Xie, Jiang
    Sun, Peishuai
    [J]. COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II, 2022, 461 : 437 - 456
  • [9] NTCS: A Real Time Flow-based Network Traffic Classification System
    Lopes Pereira, Silas Santiago
    de Castro e Silva, Jorge Luiz
    Bessa Maia, Jose Everardo
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 368 - 371
  • [10] Flow-based network traffic generation using Generative Adversarial Networks
    Ring, Markus
    Schloer, Daniel
    Landes, Dieter
    Hotho, Andreas
    [J]. COMPUTERS & SECURITY, 2019, 82 : 156 - 172