Machine learning for encrypted malicious traffic detection: Approaches, datasets and comparative study

被引:40
|
作者
Wang, Zihao [1 ]
Fok, Kar Wai [1 ]
Thing, Vrizlynn L. L. [1 ]
机构
[1] Cybersecur Strateg Technol Centr ST Engn Singapor, Singapore, Singapore
关键词
encrypted malicious traffic detection; traffic classification; machine learning; deep learning; NEURAL-NETWORKS; CLASSIFICATION; INTERNET;
D O I
10.1016/j.cose.2021.102542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As people's demand for personal privacy and data security becomes a priority, encrypted traffic has become mainstream in the cyber world. However, traffic encryption is also shielding malicious and illegal traffic introduced by adversaries, from being detected. This is especially so in the post-COVID-19 environment where malicious traffic encryption is growing rapidly. Common security solutions that rely on plain payload content analysis such as deep packet inspection are rendered useless. Thus, machine learning based approaches have be-come an important direction for encrypted malicious traffic detection. In this paper, we formulate a universal framework of machine learning based encrypted malicious traffic detection techniques and provided a systematic review. Furthermore, current research adopts different datasets to train their models due to the lack of well-recognized datasets and feature sets. As a result, their model performance cannot be compared and analyzed reliably. Therefore, in this paper, we analyse, process and combine datasets from 5 different sources to generate a comprehensive and fair dataset to aid future research in this field. On this basis, we also implement and compare 10 encrypted malicious traffic detection algorithms. We then discuss challenges and propose future directions of research. (C) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:22
相关论文
共 50 条
  • [31] A Comparative Study on the Impact of Adversarial Machine Learning Attacks on Contemporary Intrusion Detection Datasets
    Pujari M.
    Pacheco Y.
    Cherukuri B.
    Sun W.
    [J]. SN Computer Science, 3 (5)
  • [32] A Review on Machine Learning Approaches for Network Malicious Behavior Detection in Emerging Technologies
    Rabbani, Mahdi
    Wang, Yongli
    Khoshkangini, Reza
    Jelodar, Hamed
    Zhao, Ruxin
    Bagheri Baba Ahmadi, Sajjad
    Ayobi, Seyedvalyallah
    [J]. ENTROPY, 2021, 23 (05)
  • [33] Machine Learning Approaches to Malicious PowerShell Scripts Detection and Feature Combination Analysis
    Hung, Hsiang-Hua
    Chen, Jiann-Liang
    Ma, Yi-Wei
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (01): : 167 - 173
  • [34] Empirical Study on Malicious URL Detection Using Machine Learning
    Patgiri, Ripon
    Katari, Hemanth
    Kumar, Ronit
    Sharma, Dheeraj
    [J]. DISTRIBUTED COMPUTING AND INTERNET TECHNOLOGY, ICDCIT 2019, 2019, 11319 : 380 - 388
  • [35] Network Traffic Anomaly Detection using Machine Learning Approaches
    Limthong, Kriangkrai
    Tawsook, Thidarat
    [J]. 2012 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2012, : 542 - 545
  • [36] GCN-ETA: High-Efficiency Encrypted Malicious Traffic Detection
    Zheng, Juan
    Zeng, Zhiyong
    Feng, Tao
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [37] Encrypted network traffic classification based on machine learning
    Elmaghraby, Reham T.
    Aziem, Nada M. Abdel
    Sobh, Mohammed A.
    Bahaa-Eldin, Ayman M.
    [J]. AIN SHAMS ENGINEERING JOURNAL, 2024, 15 (02)
  • [38] Identification of Application in Encrypted Traffic by Using Machine Learning
    Pektas, Abdurrahman
    Acarman, Tankut
    [J]. MAN-MACHINE INTERACTIONS 5, ICMMI 2017, 2018, 659 : 545 - 554
  • [39] Black box attack and network intrusion detection using machine learning for malicious traffic
    Zhu, Yiran
    Cui, Lei
    Ding, Zhenquan
    Li, Lun
    Liu, Yongji
    Hao, Zhiyu
    [J]. COMPUTERS & SECURITY, 2022, 123
  • [40] Feature Entropy Estimation (FEE) for Malicious IoT Traffic and Detection Using Machine Learning
    Diwan, Tarun Dhar
    Choubey, Siddartha
    Hota, H. S.
    Goyal, S. B.
    Jamal, Sajjad Shaukat
    Shukla, Piyush Kumar
    Tiwari, Basant
    [J]. MOBILE INFORMATION SYSTEMS, 2021, 2021