错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Anomaly Detection Method for Integrated Encrypted Malicious Traffic Based on RFCNN-GRU

  • Huiqi Zhao,
  • Yaowen Ma,
  • Fang Fan,
  • Huajie Zhang

摘要

Although a lot of work has been devoted to the identification of malicious traffic, the identification methods for encrypted malicious traffic are few and weakly targeted, and traditional machine learning and single deep learning anomaly detection methods have been unable to achieve good results in encrypted malicious traffic. Therefore, this paper proposes an integrated deep learning anomaly detection method based on encrypted malicious traffic time series information according to the importance of features, which only considers statistical data and encrypted malicious traffic time series characteristics, without decrypting or using any payload information, so as to achieve high accuracy of encrypted malicious traffic anomaly detection. The integrated model is constructed by 1D Convolutional Neural Network, Gate Recurrent Unit and Random Forest. By analyzing the most informative features in encrypted network traffic data, the classification output value of the single feature group trained by CNN-GRU model is combined with the output probability of Random Forest Classifier according to weight. Ultimately, our model will select the detection class with the highest average output in the total classifier. The proposed RFCNN-GRU model can achieve high precision and strong robustness of encrypted malicious traffic anomaly detection under multi-classification.