Enhanced Malicious Traffic Detection in Encrypted Communication Using TLS Features and a Multi-class Classifier Ensemble

被引:2
|
作者
Kondaiah, Cheemaladinne [1 ]
Pais, Alwyn Roshan [1 ]
Rao, Routhu Srinivasa [2 ]
机构
[1] Natl Inst Technol Karnataka, Dept Comp Sci & Engn, Informat Secur Res Lab, Surathkal 575025, Karnataka, India
[2] GITAM Deemed Univ, Dept Comp Sci & Engn, Visakhapatnam 530045, Andhra Pradesh, India
关键词
TLS; 1.2; and; 1.3; RF; LSTM; Bi-LSTM; Ensemble; Malicious URLs; PHISHING DETECTION; EFFICIENT;
D O I
10.1007/s10922-024-09847-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The use of encryption for network communication leads to a significant challenge in identifying malicious traffic. The existing malicious traffic detection techniques fail to identify malicious traffic from the encrypted traffic without decryption. The current research focuses on feature extraction and malicious traffic classification from the encrypted network traffic without decryption. In this paper, we propose an ensemble model using Deep Learning (DL), Machine Learning (ML), and self-attention-based methods. Also, we propose novel TLS features extracted from the network and perform experimentation on the ensemble model. The experimental results demonstrated that the ML-based (RF, LGBM, XGB) ensemble model achieved a significant accuracy of 94.85% whereas the other ensemble model using RF, LSTM, and Bi-LSTM with self-attention technique achieved an accuracy of 96.71%. To evaluate the efficacy of our proposed models, we curated datasets encompassing both phishing, legitimate and malware websites, leveraging features extracted from TLS 1.2 and 1.3 traffic without decryption.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] Multi-class Traffic Morphing for Encrypted VoIP Communication
    Moore, W. Brad
    Tan, Henry
    Sherr, Micah
    Maloof, Marcus A.
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY (FC 2015), 2015, 8975 : 65 - 85
  • [2] TLS fingerprint for encrypted malicious traffic detection with attributed graph kernel
    Yu, Linxiao
    Tao, Jun
    Xu, Yifan
    Sun, Weice
    Wang, Zuyan
    COMPUTER NETWORKS, 2024, 247
  • [3] Detection of Android Malicious Obfuscation Applications Based on Multi-class Features
    Zhao, Meichen
    2018 EIGHTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION AND MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2018), 2018, : 1795 - 1799
  • [4] Malicious Traffic Detection in IoT and Local Networks Using Stacked Ensemble Classifier
    Indrasiri, R. D. Pubudu L.
    Lee, Ernesto
    Rupapara, Vaibhav
    Rustam, Furqan
    Ashraf, Imran
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (01): : 489 - 515
  • [5] A Scalable Genetic Programming Multi-class Ensemble Classifier
    Kumar, D. J. Nagendra
    Satapathy, Suresh Chandra
    Murthy, J. V. R.
    2009 WORLD CONGRESS ON NATURE & BIOLOGICALLY INSPIRED COMPUTING (NABIC 2009), 2009, : 1200 - +
  • [6] Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features
    Hong, Yueping
    Li, Qi
    Yang, Yanqing
    Shen, Meng
    INFORMATION SCIENCES, 2023, 644
  • [7] Early multi-class ensemble-based fake news detection using content features
    Rezaei, Sajjad
    Kahani, Mohsen
    Behkamal, Behshid
    Jalayer, Abdulrahman
    SOCIAL NETWORK ANALYSIS AND MINING, 2022, 13 (01)
  • [8] Early multi-class ensemble-based fake news detection using content features
    Sajjad Rezaei
    Mohsen Kahani
    Behshid Behkamal
    Abdulrahman Jalayer
    Social Network Analysis and Mining, 13
  • [9] An Enhanced Anomaly Detection in Web Traffic Using a Stack of Classifier Ensemble
    Tama, Bayu Adhi
    Nkenyereye, Lewis
    Islam, S. M. Riazul
    Kwak, Kyung-Sup
    IEEE ACCESS, 2020, 8 : 24120 - 24134
  • [10] A Robust Multi-class Traffic Sign Detection and Classification System using Asymmetric and Symmetric features
    Jiao, Jialin
    Zheng, Zhong
    Park, Jungme
    Murphey, Yi L.
    Luo, Yun
    2009 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC 2009), VOLS 1-9, 2009, : 3421 - +