College of Electrical and Information Engineering,Hunan University,Changsha 410082,China
Show less
文章历史+
Received
Published
2023-08-22
2024-06-25
Issue Date
2026-02-12
PDF (2059K)
摘要
网络流量识别是网络管理和安全服务的基础.随着互联网的不断扩展及其复杂性的增加,传统基于规则的识别方法或流行为特征的方法正在面临着巨大挑战.受自然语言处理(Nature Language Processing, NLP)启发,本文提出了一种多特征融合的加密流量快速分类方法.该方法通过融合数据包和字节序列特征来完成网络流的特征表示,采用双元字节编码将所选特征扩展为双字节序列,增加了字节的上下文语义特征;通过与数据包特征处理相适应的池化方法来最大限度保留数据包的特征信息,从而使所提模型具有更强的抗噪能力和更精确的分类能力.本文方法分别在ISCX-2016和一个包含66个热门应用程序的私有数据集(ETD66)上进行验证,并与其他模型展开比较.结果表明:本文所提方法在ISCX-2016及ETD66上的测试精度和性能都明显优于其他流量分类模型,分别取得了98.2%和98.6%的识别准确率,从而证明了所提方法的特征提取能力和强泛化能力.
Abstract
Network traffic recognition is the foundation of network management and security services. With the continuous expansion and increasing complexity of the Internet, traditional rule-based recognition methods or based on flow behavior characteristics are facing great challenges. Inspired by natural language processing (NLP), this paper proposes a fast classification method for encrypted traffic based on multi-feature fusion. The method completes the feature representation of network flows by combining the packet characteristics of data packets and byte sequences, expands the selected features into a double-byte sequence using binary byte encoding, and adds contextual semantic features of the bytes. By using pooling methods that are suitable for packet feature processing, the proposed model can preserve the feature information of packets to the greatest extent possible, thereby enhancing its noise resistance and more accurate classification ability. The method is validated on the Information Security Center of Excellence-2016 (ISCX-2016) and a private dataset containing Encrypted Traffic Datasets for 66 popular applications(ETD66). The results show that the proposed method has significantly better accuracy and performance than other models in ISCX-2016 and ETD66, achieving accuracy of 98.2% and 98.6%, respectively, and thus proving the strong feature extraction ability and the model generalization ability.
基于报文有效负载的流量分类是根据已知的协议来生成解码器或通过已知签名和指纹信息进行模式匹配来完成流量分类任务[7].文献[8]提出基于深度包检测技术(Deep Packet Inspection, DPI)检查负载随机性的加密流量识别算法,但仅包含使用TCP/IP(Transmission Control Protocol/Internet Protocol)、HTTP(Hypertext Transfer Protocol)、SMTP(Simple Mail Transfer Protocol)和SSL(Secure Socket Layer)等加密协议的流量;文献[9]使用有效负载的特定签名字符串进行流量分类和识别,针对已知协议的流量识别取得了较高的准确率.以上方法需要通过已知协议构建分类器或解码器,耗时又费力;直接对应用层的报文负载内容进行分析,容易导致用户隐私信息的泄露,引发相关法律问题,且无法识别未知协议或应用的流量.因此随着加密技术和协议的不断改进与更新,基于报文有效负载的流量分类在实际的工程中已不再适用.
2013年Zhang等[10]设计并提出了流量袋(Bag of Flow, BoF)方法.该方法基于应用协议流的离散统计特征(报文个数、报文大小、报文间隔时间或传输比特等)开展应用协议流量分类.2015年他们又提出了一种使用流量离散统计特征来进行未知流量检测的流量分类方法(Nearest Cluster based Classifier, NCC),用于解决小型监督训练数据集中位置应用流量的分类问题[11].文献[12]设计以加密流量中数据包为单位,来统计包括数据包发送和接收字节的最大值、最小值和平均值,并提出了一种基于复合特征的流量分类的半监督方法.Taylor等[13]提出一个称为AppScanner的方法,该方法通过综合考虑数据包长度的统计特征,分别使用支持向量机和随机森林两种机器学习算法,对谷歌应用商店110种主流移动应用的分类准确率达到99%以上.Aceto等[14]在此基础上,提出了一种基于多分类器系统(Multi-Classification System, MCS)的应用分类方法来提高移动加密应用的分类效果;在对50种移动应用分类任务中,与使用单一分类器的最好效果相比,该方法在最好的情况下能够提高8.1%的F1值.文献[15]结合统计分析和机器学习技术,结合多种统计特征来提高分类的准确性,但是所提方法需要大量数据来训练模型,导致时间成本较高.文献[16]针对加密网络流量的统计分析,提出了新的解决方案,为流量监测提供了新的思路,但是该模型关注于异常流量的处理,因此无法适用于正常流量分类的任务.
ÖZDELS, DAMLA ATEŞP, ATEŞÇ,et al .Network traffic classification with flow based approach[C]//2022 30th Signal Processing and Communications Applications Conference (SIU).Safranbolu,Turkey. IEEE,2022:1-4.
[2]
CNNIC. The 52nd Statistical Report on China's Internet Development [EB/OL]2023.
CHENZ H, CHENGG, XUZ H,et al .A survey on Internet encrypted traffic detection,classification and identification[J].Chinese Journal of Computers,2023,46(5):1060-1085.(in Chinese)
[5]
WANGY Y, GAOY L, LIX Y,et al .Encrypted traffic classification model based on SwinT-CNN[C]//2023 4th International Conference on Computer Engineering and Application (ICCEA).Hangzhou,China. IEEE,2023:138-142.
ZHANGH L .Research on application layer security method of wireless network based on encrypted traffic classification[J].Network Security Technology & Application, 2023(7): 23-25.(in Chinese)
[8]
ZHOUY, SHIH L, ZHAOY H,et al .Encrypted network traffic identification based on 2D-CNN model[C]//2021 22nd Asia-Pacific Network Operations and Management Symposium (APNOMS).Tainan,Taiwan,China. IEEE,2021: 238-241.
[9]
LID, ZHUY F, LINW .Traffic identification of mobile apps based on variational autoencoder network[C]//2017 13th International Conference on Computational Intelligence and Security (CIS).Hong Kong,China. IEEE,2017: 287-291.
SUNZ J, ZHAIJ T, DAIY W .An encrypted traffic identification method based on DPI and load randomness[J]. Journal of Applied Sciences, 2019, 37(5): 711-720.(in Chinese)
[12]
ZHAOY, YANGY R, TIANB,et al .Edge intelligence based identification and classification of encrypted traffic of Internet of Things[J].IEEE Access,2021,9:21895-21903.
[13]
ZHANGJ, CHENC, XIANGY,et al .An effective network traffic classification method with unknown flow detection[J]. IEEE Transactions on Network and Service Management,2013,10(2):133-147.
[14]
ZHANGJ, CHENX, XIANGY,et al .Robust network traffic classification[J].IEEE/ACM Transactions on Networking,2015,23(4):1257-1270.
[15]
LIUH S, WANGZ X, WANGY .Semi-supervised encrypted traffic classification using composite features set[J].Journal of Networks,2012,7(8):1195-1206.
[16]
TAYLORV F, SPOLAORR, CONTIM,et al .Robust smartphone app identification via encrypted network traffic analysis[J].IEEE Transactions on Information Forensics and Security,2018,13(1):63-78.
[17]
ACETOG, CIUONZOD, MONTIERIA,et al. Traffic classification of mobile apps through multi-classification[C]//GLOBECOM 2017-2017 IEEE Global Communications Conference.Singapore. IEEE,2017:1-6.
ANWARM A, AGRAWALM, SAROHAN,et al .Attention to Traffic:network Traffic Classification using Attention-Based CNNs[C]//2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT).Delhi,India. IEEE,2023:1-6.
ZHANGX H .Research on encrypted traffic behavior analysis technology based on machine learning[D].China Electronics Technology Group Corporation Electronic Science Research Institute,2022.(in Chinese)
[22]
DRAPER-GILG, LASHKARIA H, MAMUNM S I,et al .Characterization of encrypted and VPN traffic using time-related features[C]//Proceedings of the 2nd International Conference on Information Systems Security and Privacy.February 19-21,2016.Rome,Italy.SCITEPRESS-Science and and Technology Publications,2016:407-414.
[23]
WANGW, ZHUM, WANGJ L,et al .End-to-end encrypted traffic classification with one-dimensional convolution neural networks[C]//2017 IEEE International Conference on Intelligence and Security Informatics (ISI).Beijing,China: IEEE,2017:43-48.
[24]
LIR, XIAOX, NIS G,et al .Byte segment neural network for network traffic classification[C]//2018 IEEE/ACM 26th International Symposium on Quality of Service (IWQoS).Banff,AB,Canada: IEEE,2018:1-10.
[25]
XIEG R, LIQ, JIANGY .Self-attentive deep learning method for online traffic classification and its interpretability[J].Computer Networks,2021,196:108267.
[26]
LIUC, CAOZG,XIONGG,et al .MaMPF: encrypted traffic classification based on multi-attribute markov probability fingerprints[C]//2018 IEEE/ACM 26th International Symposium on Quality of Service (IWQoS).ACM, 2018.
[27]
XIEG R, LIQ, JIANGY,et al .SAM:self-attention based deep learning method for online traffic classification[C]//Proceedings of the Workshop on Network Meets AI & ML. Virtual Event:ACM,2020:14-20.
[28]
HEH Y, YANGZ G, CHENX N .PERT:payload encoding representation from transformer for encrypted traffic classification[C]//2020 ITU Kaleidoscope:Industry-Driven Digital Transformation (ITU K).Ha Noi,Vietnam: IEEE,2020:1-8.