Incremental Network Traffic Category Models Based on Hybrid Learning Strategies
摘要
With the increasing diversity of network services and attack methodologies, network traffic classification is confronted with the dual challenges of learning new categories and maintaining knowledge of old ones. This paper proposes an incremental learning method and its system implementation, uniquely combining sample replay with knowledge distillation within our model, aimed at effectively addressing this issue. Through rationally designing hybrid strategies such as session-level data preprocessing, incremental learning strategies, and hybrid sample set maintenance methods, we achieve effective scaling and knowledge maintenance of network traffic classification models. The inclusion of knowledge distillation techniques further enhances the model’s ability to retain previously learned information while assimilating new knowledge efficiently. The model’s efficacy and superiority in incremental learning scenarios are validated through datasets involving encrypted traffic and malicious software. The results demonstrate that our approach not only maintains the integrity of knowledge about old categories but also effectively learns the characteristics of new categories, thereby enhancing the accuracy and adaptability of network traffic classification.