User Behavior Forensics on Encrypted Traffic in the Industrial Internet of Things
摘要
The Industrial Internet of Things is an emerging technology that has rapidly penetrated diverse applications. MindSphere from Siemens stands out as a leader among Industrial Internet of Things solutions. Unlike most industrial control systems, MindSphere utilizes robust encryption protocols such as SSL, TLS and even QUIC for data transmission, presenting significant challenges to traditional traffic forensic approaches. Conducting effective user behavior forensics in this context requires the identification of relevant traffic in extensive IP network flows along with the execution of fine-grained classification tasks. The challenges significantly reduce the effectiveness of mainstream encrypted traffic classification methods on MindSphere. This chapter describes a novel flow-correlation framework that is designed to automatically extract user behavior patterns from MindSphere network traffic. The approach engages a hybrid feature set encompassing statistical and sequential data to create feature vectors for flow nodes. By leveraging traffic correlation, the approach incorporates a burst time-domain mechanism to construct a communications diagram. The constituent traffic graphs are processed using a graph neural network model to enable effective classification. Comprehensive experiments demonstrate that the approach exhibits outstanding performance that surpasses state-of-the-art methods.