Encrypted traffic classification is essential for cyberspace governance. However, due to the privacy issues associated with network traffic, most organizations, such as hospitals, government agencies, and universities, are reluctant to disclose their network traffic. Malicious users can spread illegal information or commit cybercrime on the intranet via VPN or TOR. In this paper, we adopt federated learning to provide a new solution for encrypted traffic classification in darknet. Meanwhile, we introduce federated distillation to solve the problems of excessive communication overhead and Non-IID data. In addition, secret sharing is used for privacy federated distillation. By introducing sharpening coefficients, we effectively improve the robustness of the framework against data poisoning attacks and Byzantine attacks under an honest majority. We conduct extensive experiments on public dataset ISCX CICDarknet2020 and real dataset DarkCSE2023 containing popular application traffic, including VPN and Tor. Experiments show that our proposed framework achieves precision of 96.63% and recall of 96.76% in centralized setting, precision of 90.02%, and recall of 89.60% in federated setting, which is superior to other state-of-the-art methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Secure Federated Distillation Framework for Encrypted Traffic Classification

  • Long Teng,
  • Qi Feng,
  • Wei Zhao,
  • Min Luo,
  • Debiao He

摘要

Encrypted traffic classification is essential for cyberspace governance. However, due to the privacy issues associated with network traffic, most organizations, such as hospitals, government agencies, and universities, are reluctant to disclose their network traffic. Malicious users can spread illegal information or commit cybercrime on the intranet via VPN or TOR. In this paper, we adopt federated learning to provide a new solution for encrypted traffic classification in darknet. Meanwhile, we introduce federated distillation to solve the problems of excessive communication overhead and Non-IID data. In addition, secret sharing is used for privacy federated distillation. By introducing sharpening coefficients, we effectively improve the robustness of the framework against data poisoning attacks and Byzantine attacks under an honest majority. We conduct extensive experiments on public dataset ISCX CICDarknet2020 and real dataset DarkCSE2023 containing popular application traffic, including VPN and Tor. Experiments show that our proposed framework achieves precision of 96.63% and recall of 96.76% in centralized setting, precision of 90.02%, and recall of 89.60% in federated setting, which is superior to other state-of-the-art methods.