Encrypted Traffic Classification: Combining Over-and Under-Sampling through a PCA-SVM

Abid Saber, Belkacem Fergani, Moncef Abbas · 2018

VPN (Virtual Private Network) is often the most efficient and the least expensive way to maintain flexibility, integrity and confidentiality of data exchange over the Internet. It also enables users to establish private and secure connections and avoid the common geographical restrictions of certain services offered on the net. In this context, the Deep Packet Inspection techniques (DPIs) enable firewalls to filter the VPN traffic when it is not encrypted. Otherwise, it becomes difficult to do so. In this paper, we propose a method for characterizing the traffic in one step i.e., without previously dividing VPN from non-VPN. Instead, we combine over- and under-sampling followed by Principal Component Analysis (PCA). This approach allows selecting the optimum feature subset before performing an efficient traffic classification using Support Vectors Machines classifier. In order to assess our findings, 14 types of traffic were used: 7 encrypted and 7 VPN traffic categories. Accordingly, we used only time-based flow-based features. We checked the effectiveness and performances of our proposal through several experiments of different generated timeout flows of durations on the UNB ISCX data set.

Read the paper · More papers on PaperTik