Enhanced Encrypted Traffic Analysis Leveraging Graph Neural Networks and Optimized Feature Dimensionality Reduction

被引:0
|
作者
Jung, In-Su [1 ]
Song, Yu-Rae [1 ]
Jilcha, Lelisa Adeba [2 ]
Kim, Deuk-Hun [3 ]
Im, Sun-Young [4 ]
Shim, Shin-Woo [4 ]
Kim, Young-Hwan [4 ]
Kwak, Jin [5 ]
机构
[1] Ajou Univ, Dept Cyber Secur, ISAA Lab, Suwon 16499, South Korea
[2] Ajou Univ, Dept AI Convergence Network, ISAA Lab, Suwon 16499, South Korea
[3] Ajou Univ, ISAA Lab, Inst Comp & Informat Res, Suwon 16499, South Korea
[4] LIG Nex1, Seongnam 13488, South Korea
[5] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
来源
SYMMETRY-BASEL | 2024年 / 16卷 / 06期
关键词
encrypted traffic analysis (ETA); graph neural network (GNN); GraphSAGE; network traffic classification; metadata; optimized feature dimensionality reduction; CLASSIFICATION;
D O I
10.3390/sym16060733
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
With the continuously growing requirement for encryption in network environments, web browsers are increasingly employing hypertext transfer protocol security. Despite the increase in encrypted malicious network traffic, the encryption itself limits the data accessible for analyzing such behavior. To mitigate this, several studies have examined encrypted network traffic by analyzing metadata and payload bytes. Recent studies have furthered this approach, utilizing graph neural networks to analyze the structural data patterns within malicious encrypted traffic. This study proposed an enhanced encrypted traffic analysis leveraging graph neural networks which can model the symmetric or asymmetric spatial relations between nodes in the traffic network and optimized feature dimensionality reduction. It classified malicious network traffic by leveraging key features, including the IP address, port, CipherSuite, MessageLen, and JA3 features within the transport-layer-security session data, and then analyzed the correlation between normal and malicious network traffic data. The proposed approach outperformed previous models in terms of efficiency, using fewer features while maintaining a high accuracy rate of 99.5%. This demonstrates its research value as it can classify malicious network traffic with a high accuracy based on fewer features.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Research on Data Feature Processing and Detection of Encrypted Malicious Traffic in Graph Neural Networks
    Kan, Hong
    Ren, Ran
    International Journal of Network Security, 2024, 26 (06) : 985 - 991
  • [2] Accurate Decentralized Application Identification via Encrypted Traffic Analysis Using Graph Neural Networks
    Shen, Meng
    Zhang, Jinpeng
    Zhu, Liehuang
    Xu, Ke
    Du, Xiaojiang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 2367 - 2380
  • [3] Flow-Based Encrypted Network Traffic Classification With Graph Neural Networks
    Huoh, Ting-Li
    Luo, Yan
    Li, Peilong
    Zhang, Tong
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (02): : 1224 - 1237
  • [4] Feature analysis of encrypted malicious traffic
    Shekhawat, Anish Singh
    Di Troia, Fabio
    Stamp, Mark
    EXPERT SYSTEMS WITH APPLICATIONS, 2019, 125 : 130 - 141
  • [5] Neural networks for dimensionality reduction
    Pal, NR
    Kumar, EV
    PROGRESS IN CONNECTIONIST-BASED INFORMATION SYSTEMS, VOLS 1 AND 2, 1998, : 221 - 224
  • [6] Feature Extraction for Dimensionality Reduction in Cellular Networks Performance Analysis
    de-la-Bandera, Isabel
    Palacios, David
    Mendoza, Jessica
    Barco, Raquel
    SENSORS, 2020, 20 (23) : 1 - 10
  • [7] Encrypted Traffic Classification Using Graph Convolutional Networks
    Mo, Shuang
    Wang, Yifei
    Xiao, Ding
    Wu, Wenrui
    Fan, Shaohua
    Shi, Chuan
    ADVANCED DATA MINING AND APPLICATIONS, 2020, 12447 : 207 - 219
  • [8] An approach to feature dimensionality reduction based on radial basis function neural networks
    Li, Tao
    Xiao, Nanfeng
    Journal of Convergence Information Technology, 2012, 7 (03) : 117 - 126
  • [9] Fine-Grained Encrypted Traffic Classification Using Dual Embedding and Graph Neural Networks
    Liu, Zhengyang
    Wei, Qiang
    Song, Qisong
    Duan, Chaoyuan
    ELECTRONICS, 2025, 14 (04):
  • [10] SAT-Net: A staggered attention network using graph neural networks for encrypted traffic classification
    Li, Zhiyuan
    Zhao, Hongyi
    Zhao, Jingyu
    Jiang, Yuqi
    Bu, Fanliang
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 233