Enhanced Encrypted Traffic Analysis Leveraging Graph Neural Networks and Optimized Feature Dimensionality Reduction

被引:0
|
作者
Jung, In-Su [1 ]
Song, Yu-Rae [1 ]
Jilcha, Lelisa Adeba [2 ]
Kim, Deuk-Hun [3 ]
Im, Sun-Young [4 ]
Shim, Shin-Woo [4 ]
Kim, Young-Hwan [4 ]
Kwak, Jin [5 ]
机构
[1] Ajou Univ, Dept Cyber Secur, ISAA Lab, Suwon 16499, South Korea
[2] Ajou Univ, Dept AI Convergence Network, ISAA Lab, Suwon 16499, South Korea
[3] Ajou Univ, ISAA Lab, Inst Comp & Informat Res, Suwon 16499, South Korea
[4] LIG Nex1, Seongnam 13488, South Korea
[5] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
来源
SYMMETRY-BASEL | 2024年 / 16卷 / 06期
关键词
encrypted traffic analysis (ETA); graph neural network (GNN); GraphSAGE; network traffic classification; metadata; optimized feature dimensionality reduction; CLASSIFICATION;
D O I
10.3390/sym16060733
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
With the continuously growing requirement for encryption in network environments, web browsers are increasingly employing hypertext transfer protocol security. Despite the increase in encrypted malicious network traffic, the encryption itself limits the data accessible for analyzing such behavior. To mitigate this, several studies have examined encrypted network traffic by analyzing metadata and payload bytes. Recent studies have furthered this approach, utilizing graph neural networks to analyze the structural data patterns within malicious encrypted traffic. This study proposed an enhanced encrypted traffic analysis leveraging graph neural networks which can model the symmetric or asymmetric spatial relations between nodes in the traffic network and optimized feature dimensionality reduction. It classified malicious network traffic by leveraging key features, including the IP address, port, CipherSuite, MessageLen, and JA3 features within the transport-layer-security session data, and then analyzed the correlation between normal and malicious network traffic data. The proposed approach outperformed previous models in terms of efficiency, using fewer features while maintaining a high accuracy rate of 99.5%. This demonstrates its research value as it can classify malicious network traffic with a high accuracy based on fewer features.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] MAppGraph: Mobile-App Classification on Encrypted Network Traffic using Deep Graph Convolution Neural Networks
    Thai-Dien Pham
    Thien-Lac Ho
    Tram Truong-Huu
    Tien-Dung Cao
    Hong-Linh Truong
    37TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2021, 2021, : 1025 - 1038
  • [22] Feature reduction in graph analysis
    Piriyakul, Rapepun
    Piamsa-nga, Punpiti
    SENSORS, 2008, 8 (08): : 4758 - 4773
  • [23] Encrypted Traffic Classification Based on Text Convolution Neural Networks
    Song, Mingze
    Ran, Jing
    Li, Shulan
    PROCEEDINGS OF 2019 IEEE 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2019), 2019, : 432 - 436
  • [24] An Optimized VTCR Feature Dimensionality Reduction Algorithm Based on Information Entropy
    Mou, Shaohao
    Jia, Weikuan
    Tian, Yuyu
    Zheng, Yuanjie
    Zhao, Yanna
    ENGINEERING LETTERS, 2020, 28 (01) : 10 - 15
  • [25] STOG: A Traffic Prediction Scheme Based on Spatio-Temporal Optimized Graph Neural Networks
    Hu, Shuting
    Yu, Ze
    Zhou, Danyang
    Zhou, Yi
    Cheng, Nan
    Lu, Ning
    2021 IEEE 94TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2021-FALL), 2021,
  • [26] Experimental Probing of Graph Convolutional Neural Networks Architectures for Traffic Analysis
    Salehi, Bahare
    Sakr, Mahmoud
    2024 IEEE 40TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING WORKSHOP, ICDEW, 2024, : 32 - 39
  • [27] Enhanced graph-based dimensionality reduction with repulsion Laplaceans
    Kokiopoulou, E.
    Saad, Y.
    PATTERN RECOGNITION, 2009, 42 (11) : 2392 - 2402
  • [28] Graph-preserving shortest feature line segment for dimensionality reduction
    Li, Wei
    Ruan, Qiuqi
    Wan, Jun
    NEUROCOMPUTING, 2013, 110 : 80 - 91
  • [29] Efficient BiSRU Combined With Feature Dimensionality Reduction for Abnormal Traffic Detection
    Ding, Pengpeng
    Li, Jinguo
    Wen, Mi
    Wang, Liangliang
    Li, Hongjiao
    IEEE ACCESS, 2020, 8 : 164414 - 164427
  • [30] A hybrid approach for intrusion detection in vehicular networks using feature selection and dimensionality reduction with optimized deep learning
    Hassan, Fayaz
    Syed, Zafi Sherhan
    Memon, Aftab Ahmed
    Alqahtany, Saad Said
    Ahmed, Nadeem
    Al Reshan, Mana Saleh
    Asiri, Yousef
    Shaikh, Asadullah
    PLOS ONE, 2025, 20 (02):