The proliferation of various encrypted protocols has resulted in a significant portion of network traffic being protected from conventional inspection methods, including deep packet inspection (DPI) and port-based inspection. Encryption improves security and privacy; however, it presents considerable challenges for network administrators and security professionals regarding the monitoring, management, and classification of network traffic. Various deep learning approaches have demonstrated high performance in the classification of encrypted network traffic, necessitating substantial amounts of labeled data. Labeled data of network traffic is rarely available or infrequently accessible. A previous research demonstrated the potential to eliminate the necessity for this extensive labeled data. However, they utilized a substantial number of packets, which may elevate the classification latency. This paper presents a transfer learning approach utilizing LSTM (Long Short-Term Memory) for classifying network traffic flows with minimal number of packets and also to eliminate the need of large labeled dataset. We conducted three distinct sub-flow extraction methods to perform encrypted network traffic classification in three different cases and also introduced unique packet selection strategy for the sub-flows to perform the classification with fewer packets. All three sub-flow extraction methods exhibit superior performance, even with a limited number of packets, which is crucial for minimizing classification latency.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Encrypted Network Traffic Classification for QUIC Protocol: A Transfer Learning Approach

  • Aman Ullah Bhuiyan,
  • Ashikun Nabi,
  • Raqeebir Rab,
  • Abderrahmane Leshob,
  • Tasnim Mahmud,
  • Adil Ahmed Khan

摘要

The proliferation of various encrypted protocols has resulted in a significant portion of network traffic being protected from conventional inspection methods, including deep packet inspection (DPI) and port-based inspection. Encryption improves security and privacy; however, it presents considerable challenges for network administrators and security professionals regarding the monitoring, management, and classification of network traffic. Various deep learning approaches have demonstrated high performance in the classification of encrypted network traffic, necessitating substantial amounts of labeled data. Labeled data of network traffic is rarely available or infrequently accessible. A previous research demonstrated the potential to eliminate the necessity for this extensive labeled data. However, they utilized a substantial number of packets, which may elevate the classification latency. This paper presents a transfer learning approach utilizing LSTM (Long Short-Term Memory) for classifying network traffic flows with minimal number of packets and also to eliminate the need of large labeled dataset. We conducted three distinct sub-flow extraction methods to perform encrypted network traffic classification in three different cases and also introduced unique packet selection strategy for the sub-flows to perform the classification with fewer packets. All three sub-flow extraction methods exhibit superior performance, even with a limited number of packets, which is crucial for minimizing classification latency.