How much training data is enough to move a ML-based classifier to a different network?
Ali Safari Khatouni, Nur Zincir Heywood · Procedia Computer Science · 2019
Analyzing and understanding network traffic is a crucial requirement for different network and security monitoring tools. The evolution of Internet services and protocols has caused traditional traffic analysis and classification approaches to be ineffective on traffic related to social media, streaming audio and video services. Key causes include: (i) the rise in the usage of dynamic port numbers by different applications causing port number based classification inaccurate, and (ii) the increase in encrypted traffic causing the payload to be opaque and therefore, deep packet inspection to fall short. This research aims to study how to leverage machine learning based network traffic analysis and classification work in the presence of encrypted services. In this work, we implement and evaluate a decision tree based machine learning classifier for encrypted social media, video, and audio traffic identification without using IP addresses, Port Numbers, application header fields, and payload. The extensive evaluations present high accuracy to classify not only the aforementioned services but also to investigate how much more training is necessary when such a classifier is moved to a new network in terms of location, time, and traffic volume.