Addressing the issues of high computational overhead, prolonged model training time, and coarse granularity in existing encrypted network traffic perception technologies, this paper proposes a fine-grained identification mechanism for encrypted network traffic based on data fingerprints and multi-classifier decision-making. By utilizing rules for extracting data fingerprints from encrypted network traffic, this mechanism achieves feature extraction of encrypted network traffic data, allowing for precise characterization of encrypted network flow data at the transport layer. Subsequently, a fine-grained analysis method for encrypted network traffic based on multi-classifier decision-making was designed. By integrating several small model encryption traffic classifier algorithms such as SVM and KNN algorithms, and using the voting decision of multiple classifiers, this method conducts a fine-grained analysis of encrypted network traffic. It identifies and analyzes the encryption status of network flows, the application types of encrypted network flows, and the content types of encrypted network flows, providing robust decision support for subsequent malicious network traffic perception. The method achieved commendable experimental results in the authoritative dataset ISCX VPN-nonVPN, verifying the effectiveness of this mechanism.
No takes yet. Share an insight, caveat, or question.
Wu et al. (2024) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: