Academic Journal

Accurate Encrypted Malicious Traffic Identification via Traffic Interaction Pattern Using Graph Convolutional Network

التفاصيل البيبلوغرافية
العنوان: Accurate Encrypted Malicious Traffic Identification via Traffic Interaction Pattern Using Graph Convolutional Network
المؤلفون: Guoqiang Ren, Guang Cheng, Nan Fu
المصدر: Applied Sciences; Volume 13; Issue 3; Pages: 1483
بيانات النشر: Multidisciplinary Digital Publishing Institute
سنة النشر: 2023
المجموعة: MDPI Open Access Publishing
مصطلحات موضوعية: encrypted malicious traffic identification, traffic interaction pattern, graph feature, deep learning, graph convolutional network
جغرافية الموضوع: agris
الوصف: Telecommuting and telelearning have gradually become mainstream lifestyles in the post-epidemic era. The extensive interconnection of massive terminals gives attackers more opportunities, which brings more significant challenges to network traffic security analysis. The existing attacks, often using encryption technology and distributed attack methods, increase the number and complexity of attacks. However, the traditional methods need more analysis of encrypted malicious traffic interaction patterns and cannot explore the potential correlations of interaction patterns in a macroscopic and comprehensive manner. Anyway, the changes in interaction patterns caused by attacks also need further study. Therefore, to achieve accurate and effective identification of attacks, it is essential to comprehensively describe the interaction patterns of malicious traffic and portray the relations of interaction patterns with the appearance of attacks. We propose a method for classifying attacks based on the traffic interaction attribute graph, named G-TIAG. At first, the G-TIAG studies interaction patterns of traffic describes the construction rule of the graphs and selects the attributive features of nodes in each graph. Then, it uses a convolutional graph network with a GRU and self-attention to classify benign data and different attacks. Our approach achieved the best classification results, with 89% accuracy and F1-Score, 88% recall, respectively, on publicly available datasets. The improvement is about 7% compared to traditional machine learning classification results and about 6% compared to deep learning classification results, which finally successfully achieved the classification of attacks.
نوع الوثيقة: text
وصف الملف: application/pdf
اللغة: English
Relation: Computing and Artificial Intelligence; https://dx.doi.org/10.3390/app13031483
DOI: 10.3390/app13031483
الاتاحة: https://doi.org/10.3390/app13031483
Rights: https://creativecommons.org/licenses/by/4.0/
رقم الانضمام: edsbas.2459DBC7
قاعدة البيانات: BASE