LaFFT: Length-Aware FFT Based Fingerprinting for Encrypted Network Traffic Classification
Chang Liu, Zigang Cao, Zhen Li, Gang Xiong · 2018
Encrypted traffic classficiation has become an emergent and challenging task for network monitoring and management. Traditional classification methods for encrypted traffic rely on complex statistical characteristic construction and in-depth packet resolution, which produce huge loads. In this paper, we develop Length-aware FFT (LaFFT) fingerprinting to identify different encrypted application traffic with packet length sequences. We apply FFT to packet length sequences to generate the frequency domain vectors as LaFFT features. We verify the distinguishability of LaFFT fingerprinting by data analysis. Furthermore, the linear inseparability and the front superiority of LaFFT fingerprinting are demonstrated by comprehensive experiments. In the real-world dataset, the LaFFT fingerprinting with random forest classifier can achieve 96.8% TPR, 0.32% FPR and 0.959 FFT, which significantly outperform the state-of-the-art methods.