Semi-Supervised Encrypted Malicious Traffic Detection Based on Multimodal Traffic Characteristics

被引:0
|
作者
Liu, Ming [1 ]
Yang, Qichao [1 ]
Wang, Wenqing [1 ]
Liu, Shengli [1 ]
机构
[1] Informat Engn Univ, Zhengzhou 450001, Peoples R China
关键词
encrypted malicious traffic detection; semi-supervised learning; multimodal features; network security; NETWORK;
D O I
10.3390/s24206507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The exponential growth of encrypted network traffic poses significant challenges for detecting malicious activities online. The scale of emerging malicious traffic is significantly smaller than that of normal traffic, and the imbalanced data distribution poses challenges for detection. However, most existing methods rely on single-category features for classification, which struggle to detect covert malicious traffic behaviors. In this paper, we introduce a novel semi-supervised approach to identify malicious traffic by leveraging multimodal traffic characteristics. By integrating the sequence and topological information inherent in the traffic, we achieve a multifaceted representation of encrypted traffic. We design two independent neural networks to learn the corresponding sequence and topological features from the traffic. This dual-feature extraction enhances the model's robustness in detecting anomalies within encrypted traffic. The model is trained using a joint strategy that minimizes both the reconstruction error from the autoencoder and the classification loss, allowing it to effectively utilize limited labeled data alongside a large amount of unlabeled data. A confidence-estimation module enhances the classifier's ability to detect unknown attacks. Finally, our method is evaluated on two benchmark datasets, UNSW-NB15 and CICIDS2017, under various scenarios, including different training set label ratios and the presence of unknown attacks. Our model outperforms other models by 3.49% and 5.69% in F1 score at labeling rates of 1% and 0.1%, respectively.
引用
收藏
页数:21
相关论文
共 50 条
  • [31] ByteSGAN: A semi-supervised Generative Adversarial Network for encrypted traffic classification in SDN Edge Gateway
    Wang, Pan
    Wang, Zixuan
    Ye, Feng
    Chen, Xuejiao
    COMPUTER NETWORKS, 2021, 200
  • [32] Semi-supervised and compound classification of network traffic
    Zhang, J. (jun.zhang@deakin.edu.au), 1600, Inderscience Enterprises Ltd., 29, route de Pre-Bois, Case Postale 856, CH-1215 Geneva 15, CH-1215, Switzerland (07):
  • [33] Hungarian Traffic Sign Detection and Classification using Semi-Supervised Learning
    Kovacs, Levente
    Kertesz, Gabor
    IEEE 15TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI 2021), 2021, : 437 - 441
  • [34] Encrypted malicious traffic detection based on natural language processing and deep learning
    Zang, Xiaodong
    Wang, Tongliang
    Zhang, Xinchang
    Gong, Jian
    Gao, Peng
    Zhang, Guowei
    COMPUTER NETWORKS, 2024, 250
  • [35] Encrypted Malicious Traffic Detection Based on Graph Convolutional Network and Temporal Dissection
    Liu, Yuchen
    Wang, Shanshan
    Jin Au-yeung
    Chen, Zhenxiang
    PROCEEDINGS OF THE 2024 27 TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, CSCWD 2024, 2024, : 187 - 192
  • [36] Feature analysis of encrypted malicious traffic
    Shekhawat, Anish Singh
    Di Troia, Fabio
    Stamp, Mark
    EXPERT SYSTEMS WITH APPLICATIONS, 2019, 125 : 130 - 141
  • [37] Malicious domain detection based on semi-supervised learning and parameter optimization
    Liao, Renjie
    Wang, Shuo
    IET COMMUNICATIONS, 2024, 18 (06) : 386 - 397
  • [38] Semi-supervised Malicious Domain Detection Based on Meta Pseudo Labeling
    Gao, Yi
    Yuan, Fangfang
    Yang, Jinglin
    Wang, Dakui
    Cao, Cong
    Liu, Yanbing
    COMPUTATIONAL SCIENCE, ICCS 2024, PT II, 2024, 14833 : 312 - 324
  • [39] Detection of Encrypted Malicious Network Traffic using Machine Learning
    De Lucia, Michael J.
    Cotton, Chase
    MILCOM 2019 - 2019 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2019,
  • [40] Effectiveness Evaluation of Evasion Attack on Encrypted Malicious Traffic Detection
    Liu, Jian
    Xiao, Qingsai
    Jiang, Zhengwei
    Yao, Yepeng
    Wang, Qiuyun
    2022 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2022, : 1158 - 1163