Encrypted Malware Traffic Detection via Multi-view Learning
摘要
With encryption protocols widely adopted in network communication, traditional deep packet inspection methods frequently fail to detect malware traffic. Recent statistical approaches address this issue by classifying malware traffic based on features extracted from observable data fields. However, these approaches ignore potential redundancies in the features. Addressing this issue, we propose a multi-view classification approach to detect TLS encrypted malware traffic. It first extracts 21 features separated into three semantic sets/views (packet feature, TLS feature or certificate feature). Then a multi-view neural network integrates the complementary information from the three views. Nevertheless, we conduct extensive experiments demonstrating the method’s efficacy.