期刊文献+

基于图表示的恶意TLS流量检测方法

Malicious TLS Traffic Detection Based on Graph Representation
下载PDF
导出
摘要 出于隐私保护的需要,加密服务日益普及,然而这也为恶意流量提供了隐藏自身的渠道.因此,加密恶意流量识别成为网络管理的重要任务.目前,一些基于机器学习和深度学习的主流技术已经取得了良好的效果,然而,这些方法大多忽略了流量的结构特性,也未对加密协议进行深入分析.针对这一问题,提出了一种针对安全套接层/传输层安全(secure sockets layer/transport layer security, SSL/TLS)流量的图表示方法,总结TLS流量关键特征,并从流的源IP、目的端口、数据包数等多个属性角度考虑流量关联性.在此基础上,建立了一个基于图卷积神经网络(graph convolutional networks, GCN)的加密恶意流量识别框架GCN-RF.该方法将流量转化为图结构,综合利用流量的结构信息和节点特征进行识别与分类.在真实的公共数据集上的实验结果表明,该方法的分类准确率高于目前的主流模型. Owing to the need for privacy protection,encryption services online are becoming increasingly popular.However,this also provides an avenue for malicious traffic to hide itself.As a result,the identification of encrypted malicious traffic has become an important task for network management.Currently,some mainstream techniques based on machine learning and deep learning have achieved good results.However,most of these methods ignore the structure of traffic and do not provide in-depth analysis of encryption protocols.To address this problem,this paper proposes a graph representation method for SSLTLS traffic,summarizes the key features of TLS traffic and considers traffic correlation from the perspective of multiple attributes such as source IP,destination port and packet count of the flow.Furthermore,this paper establishes a malicious traffic identification framework GCN-RF based on graph convolutional neural network and random forest algorithm.This method transforms traffic into graph structure,integrates the structural information and node features of traffic for identification and classification.Experimental results on real public datasets show that the classification accuracy of this method is higher than that of current mainstream models.
作者 赵荻 尹志超 崔苏苏 曹中华 卢志刚 Zhao Di;Yin Zhichao;Cui Susu;Cao Zhonghua;and Lu Zhigang(Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100085;School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100049;Beijing China Realm Security Incorporated Company,Beijing 100085)
出处 《信息安全研究》 CSCD 北大核心 2024年第3期209-215,共7页 Journal of Information Security Research
基金 国家重点研发计划项目(2021YFF0307203) 中国科学院战略性先导科技专项(C类)项目(XDC02040100) 中国科学院信息工程研究所攀登计划项目(E3Z0101)。
关键词 加密流量 恶意流量 图卷积神经网络 深度学习 加密协议 encrypted traffic malicious traffic graph convolutional networks deep learning encrypted protocols
  • 相关文献

参考文献2

二级参考文献16

共引文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部