APT Encrypted Traffic Detection Method based on Two-Parties and Multi-Session for IoT

02/26/2023
by   Junfeng Xu, et al.
0

APT traffic detection is an important task in network security domain, which is of great significance in the field of enterprise security. Most APT traffic uses encrypted communication protocol as data transmission medium, which greatly increases the difficulty of detection. This paper analyzes the existing problems of current APT encrypted traffic detection methods based on machine learning, and proposes an APT encrypted traffic detection method based on two parties and multi-session. This method only needs to extract a small amount of features, such as session sequence, session time interval, upstream and downstream data size, and convert them into images. Then convolutional neural network method can be used to realize image recognition. Thus, network traffic identification can be realized too. In the preliminary test of five experiments, this method achieves good experimental results, which verifies the effectiveness of the method.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/26/2019

TEST: an End-to-End Network Traffic Examination and Identification Framework Based on Spatio-Temporal Features Extraction

With more encrypted network traffic gets involved in the Internet, how t...
research
03/17/2022

Machine Learning for Encrypted Malicious Traffic Detection: Approaches, Datasets and Comparative Study

As people's demand for personal privacy and data security becomes a prio...
research
11/27/2019

PacketCGAN: Exploratory Study of Class Imbalance for Encrypted Traffic Classification Using CGAN

With more and more adoption of Deep Learning (DL) in the field of image ...
research
02/11/2020

Session: A Model for End-To-End Encrypted Conversations With Minimal Metadata Leakage

Session is an open-source, public-key-based secure messaging application...
research
04/12/2020

SFE-GACN: A Novel Unknown Attack Detection Method Using Intra Categories Generation in Embedding Space

In the encrypted network traffic intrusion detection, deep learning base...
research
12/14/2020

Differentiation of Sliding Rescaled Ranges: New Approach to Encrypted and VPN Traffic Detection

We propose a new approach to traffic preprocessing called Differentiatio...
research
02/25/2020

Protocol Proxy: An FTE-based Covert Channel

In a hostile network environment, users must communicate without being d...

Please sign up or login with your details

Forgot password? Click here to reset