<p>Encrypted traffic detection and classification play a crucial role in modern network security, mainly as encryption protocols such as TLS, VPNs, and Tor become ubiquitous. This paper presents a novel approach integrating Hybrid Attention-based feature enhancement with a LightGBM classifier to improve the interpretability and performance of encrypted traffic classification. Despite advancements in machine learning (ML) and deep learning (DL) techniques, existing models face scalability, explainability, and generalization limitations across diverse network environments. To address these challenges, we develop an augmented dataset that integrates multiple publicly available encrypted traffic datasets, enhancing model robustness and diversity. Additionally, we incorporate Explainable AI (XAI) techniques, including SHAP and LIME, to analyze the importance of features and refine classification strategies. Our experimental evaluation demonstrates the proposed model’s superiority in binary and multi-class classification tasks, outperforming state-of-the-art approaches. This study highlights the significance of adaptive classification models and optimized feature representations in encrypted traffic detection, setting the stage for future advancements in network security and encrypted traffic analysis.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Hybrid attention-enhanced explainable model for encrypted traffic detection and classification

  • Adit Sharma,
  • Arash Habibi Lashkari

摘要

Encrypted traffic detection and classification play a crucial role in modern network security, mainly as encryption protocols such as TLS, VPNs, and Tor become ubiquitous. This paper presents a novel approach integrating Hybrid Attention-based feature enhancement with a LightGBM classifier to improve the interpretability and performance of encrypted traffic classification. Despite advancements in machine learning (ML) and deep learning (DL) techniques, existing models face scalability, explainability, and generalization limitations across diverse network environments. To address these challenges, we develop an augmented dataset that integrates multiple publicly available encrypted traffic datasets, enhancing model robustness and diversity. Additionally, we incorporate Explainable AI (XAI) techniques, including SHAP and LIME, to analyze the importance of features and refine classification strategies. Our experimental evaluation demonstrates the proposed model’s superiority in binary and multi-class classification tasks, outperforming state-of-the-art approaches. This study highlights the significance of adaptive classification models and optimized feature representations in encrypted traffic detection, setting the stage for future advancements in network security and encrypted traffic analysis.