Semi-Supervised Encrypted Malicious Traffic Detection Based on Multimodal Traffic Characteristics

被引:0
|
作者
Liu, Ming [1 ]
Yang, Qichao [1 ]
Wang, Wenqing [1 ]
Liu, Shengli [1 ]
机构
[1] Informat Engn Univ, Zhengzhou 450001, Peoples R China
关键词
encrypted malicious traffic detection; semi-supervised learning; multimodal features; network security; NETWORK;
D O I
10.3390/s24206507
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The exponential growth of encrypted network traffic poses significant challenges for detecting malicious activities online. The scale of emerging malicious traffic is significantly smaller than that of normal traffic, and the imbalanced data distribution poses challenges for detection. However, most existing methods rely on single-category features for classification, which struggle to detect covert malicious traffic behaviors. In this paper, we introduce a novel semi-supervised approach to identify malicious traffic by leveraging multimodal traffic characteristics. By integrating the sequence and topological information inherent in the traffic, we achieve a multifaceted representation of encrypted traffic. We design two independent neural networks to learn the corresponding sequence and topological features from the traffic. This dual-feature extraction enhances the model's robustness in detecting anomalies within encrypted traffic. The model is trained using a joint strategy that minimizes both the reconstruction error from the autoencoder and the classification loss, allowing it to effectively utilize limited labeled data alongside a large amount of unlabeled data. A confidence-estimation module enhances the classifier's ability to detect unknown attacks. Finally, our method is evaluated on two benchmark datasets, UNSW-NB15 and CICIDS2017, under various scenarios, including different training set label ratios and the presence of unknown attacks. Our model outperforms other models by 3.49% and 5.69% in F1 score at labeling rates of 1% and 0.1%, respectively.
引用
收藏
页数:21
相关论文
共 50 条
  • [41] Toward identifying malicious encrypted traffic with a causality detection system
    Zeng, Zengri
    Xun, Peng
    Peng, Wei
    Zhao, Baokang
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 80
  • [42] Holidays Busy Traffic Forecasting Based on Semi-Supervised SVR Algorithm
    Lan, Jiao
    Qin, Xizhong
    Jia, Zhenhong
    Chen, Li
    2012 4TH INTERNATIONAL CONFERENCE ON ENVIRONMENTAL SCIENCE AND INFORMATION APPLICATION TECHNOLOGY (ESIAT 2012), 2013, 14 : 682 - 687
  • [43] Traffic State Identification of Intersection Based on Semi-supervised Hash Algorithm
    Zhang L.-L.
    Wang L.
    Zhao Q.
    Zhang L.-Y.
    Jiaotong Yunshu Xitong Gongcheng Yu Xinxi/Journal of Transportation Systems Engineering and Information Technology, 2020, 20 (01): : 75 - 82
  • [44] Semi-supervised anomaly traffic detection via multi-frequency reconstruction
    Lian, Xinglin
    Zheng, Yu
    Dang, Zhangxuan
    Peng, Chunlei
    Gao, Xinbo
    PATTERN RECOGNITION, 2025, 161
  • [45] Freeway Traffic Incident Detection from Cameras: A Semi-Supervised Learning Approach
    Chakraborty, Pranamesh
    Sharma, Anuj
    Hegde, Chinmay
    2018 21ST INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2018, : 1840 - 1845
  • [46] Predicting Unlabeled Traffic For Intrusion Detection Using Semi-Supervised Machine Learning
    Murthy, Chidananda P.
    Manjunatha, A. S.
    Jaiswal, Anku
    Madhu, B. R.
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2016, : 218 - 222
  • [47] Traffic Anomaly Detection Using Deep Semi-Supervised Learning at the Mobile Edge
    Pelati, Annalisa
    Meo, Michela
    Dini, Paolo
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (08) : 8919 - 8932
  • [48] Clustering Network Traffic Using Semi-Supervised Learning
    Krajewska, Antonina
    Niewiadomska-Szynkiewicz, Ewa
    ELECTRONICS, 2024, 13 (14)
  • [49] A novel semi-supervised approach for network traffic clustering
    Wang Y.
    Xiang Y.
    Zhang J.
    Yu S.
    Proceedings - 2011 5th International Conference on Network and System Security, NSS 2011, 2011, : 169 - 175
  • [50] A Novel Approach for Semi-Supervised Network Traffic Classification
    Huo, Yonghua
    Song, Chunxiao
    Zhou, Meichao
    Lv, Rui
    Yang, Yang
    2022 IEEE 14TH INTERNATIONAL CONFERENCE ON ADVANCED INFOCOMM TECHNOLOGY (ICAIT 2022), 2022, : 64 - 69