Preprocessing Method for Encrypted Traffic Based on Semisupervised Clustering

المؤلفون المشاركون

Liu, Liang
Niu, Weina
Zheng, Rongfeng
Liu, Jiayong
Liao, Shan
Li, Kai

المصدر

Security and Communication Networks

العدد

المجلد 2020، العدد 2020 (31 ديسمبر/كانون الأول 2020)، ص ص. 1-13، 13ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2020-07-27

دولة النشر

مصر

عدد الصفحات

13

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

The explosive growth in network traffic in recent times has resulted in increased processing pressure on network intrusion detection systems.

In addition, there is a lack of reliable methods for preprocessing network traffic generated by benign applications that do not steal users’ data from their devices.

To alleviate these problems, this study analyzed the differences between benign and malicious traffic produced by benign applications and malware, respectively.

To fully express these differences, this study proposed a new set of statistical features for training a clustering model.

Furthermore, to mine the communication channels generated by benign applications in batches, a semisupervised clustering method was adopted.

Using a small number of labeled samples, our method aggregated historical network traffic into two types of clusters.

The cluster that did not contain labeled malicious samples was regarded as a benign traffic cluster.

The experimental results were compared using four types of clustering algorithms.

The density-based spatial clustering of applications with noise (DBSCAN) clustering algorithm was selected to mine benign communication channels.

We also compared our method with two other methods, and the results demonstrated that the benign channels mined through our method were more reliable.

Finally, using our method, 1,811 benign transport layer security (TLS) channels were mined from 18,357 TLS communication channels.

The number of flows carried by these benign channels comprised 65.37% of the entire network flows, and no malicious flow was included in our results, which proves the effectiveness of our method.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Zheng, Rongfeng& Liu, Jiayong& Niu, Weina& Liu, Liang& Li, Kai& Liao, Shan. 2020. Preprocessing Method for Encrypted Traffic Based on Semisupervised Clustering. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-13.
https://search.emarefa.net/detail/BIM-1208603

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Zheng, Rongfeng…[et al.]. Preprocessing Method for Encrypted Traffic Based on Semisupervised Clustering. Security and Communication Networks No. 2020 (2020), pp.1-13.
https://search.emarefa.net/detail/BIM-1208603

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Zheng, Rongfeng& Liu, Jiayong& Niu, Weina& Liu, Liang& Li, Kai& Liao, Shan. Preprocessing Method for Encrypted Traffic Based on Semisupervised Clustering. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-13.
https://search.emarefa.net/detail/BIM-1208603

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1208603