While network traffic encryption can effectively protect users’ privacy and sensitive information, it can also be exploited by network attackers, posing major security risks to the Internet. Traditional methods for identifying malicious encrypted network traffic are significantly influenced by human experience, which consequently affects the results of such identification. This paper constructs a method for detecting malicious encrypted traffic based on hybrid the Swin Transformer and Convolutional Neural Network (CNN). The method combines the ability of the CNN to extract the local features with the global context modelling advantage of Swin Transformer. The experimental results indicate that the designed method for malicious encrypted traffic detection based on hybrid Swin Transformer and CNN is higher than other detection methods in relation to accuracy, precision, recall and F1 score. The proposed methodology is accurate and robust in the classification of malicious traffic.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Malicious Encrypted Traffic Detection Method Based on Hybrid CNN and Swin Transformer

  • Songming Han,
  • Ying Ling,
  • Ming Xie,
  • Shaofeng Ming,
  • Fuchuan Tang

摘要

While network traffic encryption can effectively protect users’ privacy and sensitive information, it can also be exploited by network attackers, posing major security risks to the Internet. Traditional methods for identifying malicious encrypted network traffic are significantly influenced by human experience, which consequently affects the results of such identification. This paper constructs a method for detecting malicious encrypted traffic based on hybrid the Swin Transformer and Convolutional Neural Network (CNN). The method combines the ability of the CNN to extract the local features with the global context modelling advantage of Swin Transformer. The experimental results indicate that the designed method for malicious encrypted traffic detection based on hybrid Swin Transformer and CNN is higher than other detection methods in relation to accuracy, precision, recall and F1 score. The proposed methodology is accurate and robust in the classification of malicious traffic.