Semi-Supervised Encrypted Malicious Traffic Detection Based on Multimodal Traffic Characteristics

被引:0
|
作者
Liu, Ming [1 ]
Yang, Qichao [1 ]
Wang, Wenqing [1 ]
Liu, Shengli [1 ]
机构
[1] Informat Engn Univ, Zhengzhou 450001, Peoples R China
关键词
encrypted malicious traffic detection; semi-supervised learning; multimodal features; network security; NETWORK;
D O I
10.3390/s24206507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The exponential growth of encrypted network traffic poses significant challenges for detecting malicious activities online. The scale of emerging malicious traffic is significantly smaller than that of normal traffic, and the imbalanced data distribution poses challenges for detection. However, most existing methods rely on single-category features for classification, which struggle to detect covert malicious traffic behaviors. In this paper, we introduce a novel semi-supervised approach to identify malicious traffic by leveraging multimodal traffic characteristics. By integrating the sequence and topological information inherent in the traffic, we achieve a multifaceted representation of encrypted traffic. We design two independent neural networks to learn the corresponding sequence and topological features from the traffic. This dual-feature extraction enhances the model's robustness in detecting anomalies within encrypted traffic. The model is trained using a joint strategy that minimizes both the reconstruction error from the autoencoder and the classification loss, allowing it to effectively utilize limited labeled data alongside a large amount of unlabeled data. A confidence-estimation module enhances the classifier's ability to detect unknown attacks. Finally, our method is evaluated on two benchmark datasets, UNSW-NB15 and CICIDS2017, under various scenarios, including different training set label ratios and the presence of unknown attacks. Our model outperforms other models by 3.49% and 5.69% in F1 score at labeling rates of 1% and 0.1%, respectively.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] Semi-Supervised Network Traffic Classification
    Erman, Jeffrey
    Mahanti, Anirban
    Arlitt, Martin
    Cohen, Ira
    Williamson, Carey
    SIGMETRICS'07: PROCEEDINGS OF THE 2007 INTERNATIONAL CONFERENCE ON MEASUREMENT & MODELING OF COMPUTER SYSTEMS, 2007, 35 (01): : 369 - 370
  • [22] Semi-supervised traffic identification based on affinity propagation
    Zhang, Zhen
    Wang, Bin-Qiang
    Li, Xiang-Tao
    Huang, Wan-Wei
    Zidonghua Xuebao/Acta Automatica Sinica, 2013, 39 (07): : 1100 - 1109
  • [23] CoMDet: A Contrastive Multimodal Pre-Training Approach to Encrypted Malicious Traffic Detection
    Sun, Jiakun
    Zhang, Xiaotian
    Wang, Yabo
    Ji, Shuyuan
    2024 IEEE 48TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC 2024, 2024, : 1118 - 1125
  • [24] Encrypted Malicious Traffic Detection Based on Word2Vec
    Ferriyan, Andrey
    Thamrin, Achmad Husni
    Takeda, Keiji
    Murai, Jun
    ELECTRONICS, 2022, 11 (05)
  • [25] Adversarial Malicious Encrypted Traffic Detection Based on Refined Session Analysis
    Li, Minghui
    Wu, Zhendong
    Chen, Keming
    Wang, Wenhai
    SYMMETRY-BASEL, 2022, 14 (11):
  • [26] AGAE: Unsupervised Anomaly Detection for Encrypted Malicious Traffic
    Wang, Hao
    Wang, Ye
    Gu, Zhaoquan
    Jia, Yan
    WEB AND BIG DATA, APWEB-WAIM 2024, PT IV, 2024, 14964 : 448 - 464
  • [27] Research on malicious traffic identification technology in encrypted traffic
    Zeng Y.
    Wu Z.
    Dong L.
    Liu Z.
    Ma J.
    Li Z.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2021, 48 (03): : 170 - 187
  • [28] Network traffic classification based on federated semi-supervised learning
    Wang, Zixuan
    Li, Zeyi
    Fu, Mengyi
    Ye, Yingchun
    Wang, Pan
    JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 149
  • [29] Network Abnormal Traffic Detection Model Based on Semi-Supervised Deep Reinforcement Learning
    Dong, Shi
    Xia, Yuanjun
    Peng, Tao
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (04): : 4197 - 4212
  • [30] CETP: A novel semi-supervised framework based on contrastive pre-training for imbalanced encrypted traffic classification
    Lin, Xinjie
    He, Longtao
    Gou, Gaopeng
    Yu, Jing
    Guan, Zhong
    Li, Xiang
    Guo, Juncheng
    Xiong, Gang
    COMPUTERS & SECURITY, 2024, 143