1. 西安交通大学自动化科学与工程学院,西安,710049
2. 西安交通大学智能网络与网络安全教育部重点实验室,西安,710049
: 2023-02-02。作者简介: 刘祎彤(1994—),男,博士生
王平辉(通信作者),男,教授,博士生导师。基金项目: 国家自然科学基金资助项目(61922067)
网络首发:2023-11-10,
纸质出版:2023
移动端阅览
刘祎彤, 王平辉, 赵俊舟. 采用序列特征与知识引导的未知网络应用早期识别方法[J]. 西安交通大学学报, 2023,57(11):181-193.
LIU Yitong, WANG Pinghui, ZHAO Junzhou. Early Identification of Unknown Applications Based on Sequence Features and Knowledge Guidance[J]. 2023, 57(11): 181-193.
刘祎彤, 王平辉, 赵俊舟. 采用序列特征与知识引导的未知网络应用早期识别方法[J]. 西安交通大学学报, 2023,57(11):181-193. DOI: 10.7652/xjtuxb202311018.
LIU Yitong, WANG Pinghui, ZHAO Junzhou. Early Identification of Unknown Applications Based on Sequence Features and Knowledge Guidance[J]. 2023, 57(11): 181-193. DOI: 10.7652/xjtuxb202311018.
针对现有网络流量分类方法难以在样本稀缺场景下快速识别早期未知应用这一问题
提出一种基于序列特征与知识引导的未知网络应用早期识别方法。一方面基于Transformer-encoder框架构建流量分类模型(FAIN)
该模型利用自注意力机制挖掘流量序列中数据包之间的全局依赖关系
生成具有可分辨性的流量表示向量用于分类。另一方面
为提升FAIN模型在样本稀缺场景下的适应能力
采取监督预训练与元学习相耦合的模型优化策略
赋予模型在小样本场景下快速学习流量分类任务的能力
使其满足识别早期未知网络应用的需求。在公开数据集与真实校园网流量合成的小样本数据集上进行了深入的对比实验。结果表明:所提出的流量分类模型FAIN在公开分类任务上优于现有方法
且优化后的FAIN模型在XJTU-FSTC和CSTNET数据集的5类和10类小样本分类任务上
准确率最高分别提升了16.75%、10.08%和11.57%、8.24%。该研究结果为未知网络应用的早期识别提供了有效的方法支撑。
To address the problem that the existing network traffic classification methods are not able to promptly identify early unknown applications in case of data scarcity
a method for the early identification of unknown applications based on sequence features and knowledge guidance is proposed in this paper. On the one hand
a traffic classification model
named FAIN
is constructed using the Transformer-encoder framework. By leveraging the self-attention mechanism
FAIN model effectively captures global dependencies among packets and generates distinguishable representation for classification. On the other hand
to improve the adaptability of FAIN model to data scarcity
a model optimization strategy that couples supervised pre-training with meta-learning is proposed. This strategy empowers the model to quickly learn unseen tasks in a few-shot setting. In this study
in-depth comparative experiments are conducted on few-shot datasets synthesized from real campus network traffic. The results show that the proposed FAIN traffic classification model is superior to existing methods in terms of public network traffic classification. The optimized FAIN model improves the accuracy on the 5-class and 10-class few-shot classification tasks of the XJTU-FSTC and CSTNET datasets
with the maximum accuracy increases of 16.75%
10.08% and 11.57%
8.24%
respectively. This model provides effective support for the early identification of unknown applications.
DIERKS T, RESCORLA E. The transport layer security(TLS)protocol version 1.2 [EB/OL]. [2023-01-01]. https://www.rfc-editor. org/rfc/rfc5246.
BARAKABITZE A A, AHMAD A, MIJUMBI R, et al.5G network slicing using SDN and NFV: a survey of taxonomy, architectures and future challenges [J]. Computer Networks, 2020, 167: 106984.
HÖFER C N, KARAGIANNIS G. Cloud computing services: taxonomy and comparison [J]. Journal of Internet Services and Applications, 2011, 2(2): 81-94.
Cisco. Cisco annual internet report(2018-2023)white paper [EB/OL].(2020-03-10)[ 2023-01-01]. https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/annual-internet-report/white-paper-c11-741490. html.
REZAEI S, LIU Xin. Deep learning for encrypted traffic classification: an overview [J]. IEEE Communications Magazine, 2019, 57(5): 76-81.
TAYLOR V F, SPOLAOR R, CONTI M, et al. Robust smartphone app identification via encrypted network traffic analysis [J]. IEEE Transactions on Information Forensics and Security, 2018, 13(1): 63-78.
QURESHI H N, MANALASTAS M, ZAIDI S M A, et al. Service level agreements for 5G and beyond: overview, challenges and enablers of 5G-healthcare systems [J]. IEEE Access, 2021, 9: 1044-1061.
YAN Xiaodan, XU Yang, XING Xiaofei, et al. Trustworthy network anomaly detection based on an adaptive learning rate and momentum in IIoT [J]. IEEE Transactions on Industrial Informatics, 2020, 16(9): 6182-6192.
VASWANI A, SHAZEER N, PARMAR N, et al. Attention is all you need [C]//Proceedings of the 31st International Conference on Neural Information Processing Systems. Red Hook, NY, USA: Curran Associates Inc., 2017: 6000-6010.
DEVLIN J, CHANG Mingwei, LEE K, et al. BERT: pre-training of deep bidirectional transformers for language understanding [EB/OL].(2019-05-24)[ 2023-01-01]. https://arxiv. org/abs/1810.04805.
TAN Mingxing, LE Q V. EfficientNet: rethinking model scaling for convolutional neural networks [C]//Proceedings of the 36th International Conference on Machine Learning. Chia Laguna Resort, Sardinia, Italy: PMLR, 2019: 6105-6114.
DOSOVITSKIY A, BEYER L, KOLESNIKOV A, et al. An image is worth 16x16 words: transformers for image recognition at scale [EB/OL].(2021-06-03)[2023-01-01]. https://arxiv. org/abs/2010.11929.
LOTFOLLAHI M, JAFARI SIAVOSHANI M, SHIRALI HOSSEIN ZADE R, et al. Deep packet: a novel approach for encrypted traffic classification using deep learning [J]. Soft Computing, 2020, 24(3): 1999-2012.
LIU Chang, HE Longtao, XIONG Gang, et al. FS-Net: a flow sequence network for encrypted traffic classification [C]//IEEE INFOCOM 2019-IEEE Conference on Computer Communications. Piscataway, NJ, USA: IEEE, 2019: 1171-1179.
LI Rui, XIAO Xi, NI Shiguang, et al. Byte segment neural network for network traffic classification [C]//2018 IEEE/ACM 26th International Symposium on Quality of Service(IWQoS). Piscataway, NJ, USA: IEEE, 2018: 1-10.
言洪萍, 周强, 王世豪, 等. 基于SDN的实际网络流中Tor网页复合特征提取方法 [J]. 通信学报, 2022, 43(3): 76-87.
YAN Hongping, ZHOU Qiang, WANG Shihao, et al. Composite tor traffic features extraction method of webpage in actual network flow based on SDN [J]. Journal on Communications, 2022, 43(3): 76-87.
XIAO Xi, XIAO Wentao, LI Rui, et al. EBSNN: extended byte segment neural network for network traffic classification [J]. IEEE Transactions on Dependable and Secure Computing, 2022, 19(5): 3521-3538.
张小莉, 程光, 张慰慈. 基于改进深度卷积神经网络的网络流量分类方法 [J]. 中国科学(信息科学), 2021, 51(1): 56-74.
ZHANG Xiaoli, CHENG Guang, ZHANG Weici. Network traffic classification method based on improved deep convolutional neural network [J]. Scientia Sinica(Informationis), 2021, 51(1): 56-74.
谢绒娜, 马铸鸿, 李宗俞, 等. 基于卷积神经网络的加密流量分类方法 [J]. 网络与信息安全学报, 2022, 8(6): 84-91.
XIE Rongna, MA Zhuhong, LI Zongyu, et al. Encrypted traffic classification method based on convolutional neural network [J]. Chinese Journal of Network and Information Security, 2022, 8(6): 84-91.
LI Jianfeng, ZHOU Hao, WU Shuohan, et al. FOAP: fine-grained open-world android app fingerprinting [C]//Proceedings of the 31st USENIX Security Symposium. Boston, MA: USENIX Association, 2022: 1579-1596.
段雪源, 付钰, 王坤, 等. 基于简单统计特征的LDoS攻击检测方法 [J]. 通信学报, 2022, 43(11): 53-64.
DUAN Xueyuan, FU Yu, WANG Kun, et al. et al LDoS attack detection method based on simple statistical features [J]. Journal on Communications, 2022, 43(11): 53-64.
ZHENG Wenbo, GOU Chao, YAN Lan, et al. Learning to classify: a flow-based relation network for encrypted traffic classification [C]//Proceedings of The Web Conference 2020. New York, USA: Association for Computing Machinery, 2020: 13-22.
ACETO G, CIUONZO D, MONTIERI A, et al. Mobile encrypted traffic classification using deep learning: experimental evaluation, lessons learned, and challenges [J]. IEEE Transactions on Network and Service Management, 2019, 16(2): 445-458.
SNELL J, SWERSKY K, ZEMEL R. Prototypical networks for few-shot learning [C]//Proceedings of the 31st International Conference on Neural Information Processing Systems. Red Hook, NY, USA: Curran Associates Inc., 2017: 4080-4090.
NICHOL A, ACHIAM J, SCHULMAN J. On first-order meta-learning algorithms [EB/OL].(2018-10-22)[ 2023-01-01]. https://arxiv. org/abs/1803.02999.
ZERVEAS G, JAYARAMAN S, PATEL D, et al. A transformer-based framework for multivariate time series representation learning [EB/OL].(2020-10-06)[2023-02-01].http://arxiv.org/pdf/2020.02803.pdf.
FINN C, ABBEEL P, LEVINE S. Model-agnostic meta-learning for fast adaptation of deep networks [C]//Proceedings of the 34th International Conference on Machine Learning. Chia Laguna Resort, Sardinia, Italy: PMLR, 2017: 1126-1135.
LASHKARI A H, DRAPER-GIL G, MAMUN M S I, et al. Characterization of tor traffic using time based features [C]//Proceedings of the 3rd International Conference on Information Systems Security and Privacy-ICISSP. Setúbal, Portugal: SciTePress, 2017: 253-262.
DRAPER-GIL G, LASHKARI A H, MAMUN M S I, et al. Characterization of encrypted and vpn traffic using time-related [C]//Proceedings of the 2nd International Conference on Information Systems Security and Privacy-ICISSP. Setúbal, Portugal: SciTePress, 2016: 407-414.
ANON. XJTU-FSTC dataset [EB/OL]. [2023-01-01]. https://drive. google. com/drive/folders/15gg0bvRpX3 mQjEhqsve_LOvwtJIaT-c8?usp=share_link.
LIN Xinjie, XIONG Gang, GOU Gaopeng, et al. ETBERT: A contextualized datagram representation with pre-training transformers for encrypted traffic classification [C]//Proceedings of the ACM Web Conference 2022. New York, USA: Association for Computing Machinery, 2022: 633-642.
TAYLOR V F, SPOLAOR R, CONTI M, et al. AppScanner: automatic fingerprinting of smartphone apps from encrypted network traffic [C]//2016 IEEE European Symposium on Security and Privacy(EuroSP). Piscataway, NJ, USA: IEEE, 2016: 439-454.
RIMMER V, PREUVENEERS D, JUAREZ M, et al. Automated website fingerprinting through deep learning [EB/OL].(2017-12-05)[2023-01-01]. https://arxiv. org/abs/1708.06376.
SIRINAM P, IMANI M, JUAREZ M, et al. Deep fingerprinting: undermining website fingerprinting defenses with deep learning [C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York, USA: Association for Computing Machinery, 2018: 1928-1943.
0
浏览量
24
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621