ML-based tunnel detection and tunneled application classification

01/25/2022
by   Johan Mazel, et al.
0

Encrypted tunneling protocols are widely used. Beyond business and personal uses, malicious actors also deploy tunneling to hinder the detection of Command and Control and data exfiltration. A common approach to maintain visibility on tunneling is to rely on network traffic metadata and machine learning to analyze tunnel occurrence without actually decrypting data. Existing work that address tunneling protocols however exhibit several weaknesses: their goal is to detect application inside tunnels and not tunnel identification, they exhibit limited protocol coverage (e.g. OpenVPN and Wireguard are not addressed), and both inconsistent features and diverse machine learning techniques which makes performance comparison difficult. Our work makes four contributions that address these limitations and provide further analysis. First, we address OpenVPN and Wireguard. Second, we propose a complete pipeline to detect and classify tunneling protocols and tunneled applications. Third, we present a thorough analysis of the performance of both network traffic metadata features and machine learning techniques. Fourth, we provide a novel analysis of domain generalization regarding background untunneled traffic, and, both domain generalization and adversarial learning regarding Maximum Transmission Unit (MTU).

READ FULL TEXT
research
06/21/2022

Open-Source Framework for Encrypted Internet and Malicious Traffic Classification

Internet traffic classification plays a key role in network visibility, ...
research
10/02/2019

Machine-Learning Techniques for Detecting Attacks in SDN

With the advent of Software Defined Networks (SDNs), there has been a ra...
research
06/27/2018

PIDS - A Behavioral Framework for Analysis and Detection of Network Printer Attacks

Nowadays, every organization might be attacked through its network print...
research
07/27/2018

Leveraging Machine Learning Techniques for Windows Ransomware Network Traffic Detection

Ransomware has become a significant global threat with the ransomware-as...
research
08/06/2020

nPrint: A Standard Data Representation for Network Traffic Analysis

Conventional detection and classification ("fingerprinting") problems in...
research
05/25/2018

Futuristic Classification with Dynamic Reference Frame Strategy

Classification is one of the widely used analytical techniques in data s...
research
09/15/2023

A Testbed for Automating and Analysing Mobile Devices and their Applications

The need for improved network situational awareness has been highlighted...

Please sign up or login with your details

Forgot password? Click here to reset