Machine learning for encrypted malicious traffic detection: Approaches, datasets and comparative study

被引:40
|
作者
Wang, Zihao [1 ]
Fok, Kar Wai [1 ]
Thing, Vrizlynn L. L. [1 ]
机构
[1] Cybersecur Strateg Technol Centr ST Engn Singapor, Singapore, Singapore
关键词
encrypted malicious traffic detection; traffic classification; machine learning; deep learning; NEURAL-NETWORKS; CLASSIFICATION; INTERNET;
D O I
10.1016/j.cose.2021.102542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As people's demand for personal privacy and data security becomes a priority, encrypted traffic has become mainstream in the cyber world. However, traffic encryption is also shielding malicious and illegal traffic introduced by adversaries, from being detected. This is especially so in the post-COVID-19 environment where malicious traffic encryption is growing rapidly. Common security solutions that rely on plain payload content analysis such as deep packet inspection are rendered useless. Thus, machine learning based approaches have be-come an important direction for encrypted malicious traffic detection. In this paper, we formulate a universal framework of machine learning based encrypted malicious traffic detection techniques and provided a systematic review. Furthermore, current research adopts different datasets to train their models due to the lack of well-recognized datasets and feature sets. As a result, their model performance cannot be compared and analyzed reliably. Therefore, in this paper, we analyse, process and combine datasets from 5 different sources to generate a comprehensive and fair dataset to aid future research in this field. On this basis, we also implement and compare 10 encrypted malicious traffic detection algorithms. We then discuss challenges and propose future directions of research. (C) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:22
相关论文
共 50 条
  • [21] Machine learning methods for cyber security intrusion detection: Datasets and comparative study
    Kilincer, Ilhan Firat
    Ertam, Fatih
    Sengur, Abdulkadir
    [J]. COMPUTER NETWORKS, 2021, 188
  • [22] Machine Learning Approaches to Advanced Outlier Detection in Psychological Datasets
    Abri, Khoula Al.
    Sidhu, Manjit Singh
    [J]. INTERNATIONAL JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING SYSTEMS, 2024, 15 (01) : 13 - 20
  • [23] Detecting Encrypted Traffic: A Machine Learning Approach
    Cha, Seunghun
    Kim, Hyoungshick
    [J]. INFORMATION SECURITY APPLICATIONS, WISA 2016, 2017, 10144 : 54 - 65
  • [24] Semi-Supervised Encrypted Malicious Traffic Detection Based on Multimodal Traffic Characteristics
    Liu, Ming
    Yang, Qichao
    Wang, Wenqing
    Liu, Shengli
    [J]. Sensors, 2024, 24 (20)
  • [25] Encrypted Malicious Traffic Detection Based on Word2Vec
    Ferriyan, Andrey
    Thamrin, Achmad Husni
    Takeda, Keiji
    Murai, Jun
    [J]. ELECTRONICS, 2022, 11 (05)
  • [26] Confirmation method for the detection of malicious encrypted traffic with data privacy protection
    He, Gaofeng
    Wei, Qianfeng
    Xiao, Xiancai
    Zhu, Haiting
    Xu, Bingfeng
    [J]. Tongxin Xuebao/Journal on Communications, 2022, 43 (02): : 156 - 170
  • [27] Flow Interaction Graph Analysis: Unknown Encrypted Malicious Traffic Detection
    Fu, Chuanpu
    Li, Qi
    Xu, Ke
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2024, 32 (04) : 2972 - 2987
  • [28] TLS fingerprint for encrypted malicious traffic detection with attributed graph kernel
    Yu, Linxiao
    Tao, Jun
    Xu, Yifan
    Sun, Weice
    Wang, Zuyan
    [J]. COMPUTER NETWORKS, 2024, 247
  • [29] DEV-ETA: An Interpretable Detection Framework for Encrypted Malicious Traffic
    Yang, Luming
    Fu, Shaojing
    Wang, Yongjun
    Liang, Kaitai
    Mo, Fan
    Liu, Bo
    [J]. COMPUTER JOURNAL, 2023, 66 (05): : 1213 - 1227
  • [30] Adversarial Malicious Encrypted Traffic Detection Based on Refined Session Analysis
    Li, Minghui
    Wu, Zhendong
    Chen, Keming
    Wang, Wenhai
    [J]. SYMMETRY-BASEL, 2022, 14 (11):