Cross-Layer Profiling of Encrypted Network Data for Anomaly Detection

被引:5
|
作者
Meghdouri, Fares [1 ]
Vazquez, Felix Iglesias [1 ]
Zseby, Tanja [1 ]
机构
[1] TU Wien, Vienna, Austria
关键词
Network Data Analysis; Encrypted Communications; Anomaly Detection; Machine Learning;
D O I
10.1109/DSAA49011.2020.00061
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In January 2017 encrypted Internet traffic surpassed non-encrypted traffic. Although encryption increases security, it also masks intrusions and attacks by blocking the access to packet contents and traffic features, therefore making data analysis unfeasible. In spite of the strong effect of encryption, its impact has been scarcely investigated in the field. In this paper we study how encryption affects flow feature spaces and machine learning-based attack detection. We propose a new cross-layer feature vector that simultaneously represents traffic at three different levels: application, conversation, and endpoint behavior. We analyze its behavior under TLS and IPSec encryption and evaluate the efficacy with recent network traffic datasets and by using Random Forests classifiers. The cross-layer multi-key approach shows excellent attack detection in spite of TLS encryption. When IPsec is applied, the reduced variant obtains satisfactory detection for botnets, yet considerable performance drops for other types of attacks. The high complexity of network traffic is unfeasible for monolithic data analysis solutions, therefore requiring cross-layer analysis for which the multi-key vector becomes a powerful profiling core.
引用
收藏
页码:469 / 478
页数:10
相关论文
共 50 条
  • [31] Patient Data Prioritization in the Cross-Layer Designs of Wireless Body Area Network
    Ullah, Fasee
    Abdullah, Abdul Hanan
    Jan, Muhammad Qasim
    Qureshi, Kashif Naseer
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2015, 2015
  • [32] Cross-layer ideas in wireless network designs
    Yin, M
    Tang, Y
    Yu, Q
    IEEE 2005 INTERNATIONAL SYMPOSIUM ON MICROWAVE, ANTENNA, PROPAGATION AND EMC TECHNOLOGIES FOR WIRELESS COMMUNICATIONS PROCEEDINGS, VOLS 1 AND 2, 2005, : 891 - 894
  • [33] Ignoring Encrypted Protocols: Cross-layer Prediction of Video Streaming QoE Metrics
    Chen, Junxin
    Mai, Weimin
    Lian, Xiaoqin
    Yang, Mingyu
    Sun, Qi
    Gao, Chao
    Zhang, Cong
    Chen, Xiang
    Mobile Networks and Applications, 2022, 27 (06) : 2459 - 2468
  • [34] A Cross-Layer Approach for IP Network Protection
    Zheng, Qiang
    Zhao, Jing
    Cao, Guohong
    2012 42ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2012,
  • [35] Cross-Layer Secured IoT Network and Devices
    Chze, Paul Loh Ruen
    Leong, Kan Siew
    Wee, Ang Khoon
    Sim, Elizabeth
    May, Kan Ee
    Wing, Hing Siew
    PROCEEDINGS OF THE 18TH ASIA PACIFIC SYMPOSIUM ON INTELLIGENT AND EVOLUTIONARY SYSTEMS, VOL 2, 2015, : 319 - 333
  • [36] Cross-layer design for decentralized detection in WSNs
    Ashraf Tantawy
    Xenofon Koutsoukos
    Gautam Biswas
    EURASIP Journal on Advances in Signal Processing, 2014
  • [37] Cross-layer design for decentralized detection in WSNs
    Tantawy, Ashraf
    Koutsoukos, Xenofon
    Biswas, Gautam
    EURASIP JOURNAL ON ADVANCES IN SIGNAL PROCESSING, 2014,
  • [38] Profiling-Based Big Data Workflow Optimization in a Cross-layer Coupled Design Framework
    Ye, Qianwen
    Wu, Chase Q.
    Liu, Wuji
    Hou, Aiqin
    Shen, Wei
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2020, PT III, 2020, 12454 : 197 - 217
  • [39] Intrusion Detection Over Encrypted Network Data
    Karacay, Leyli
    Savas, Erkay
    Alptekin, Halit
    COMPUTER JOURNAL, 2020, 63 (04): : 604 - 619
  • [40] Multi-scale cross-layer fusion and center position network for pedestrian detection
    Liu, Qian
    Qi, Youwei
    Wang, Cunbao
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (01)