A New Semi-supervised Approach for Network Encrypted Traffic Clustering and Classification
Kunda Lin, Xiaolong Xu, Yu Jiang · 2022 IEEE 25th International Conference on Computer Supported Cooperative Work in Design (CSCWD) · 2022
Encrypted network traffic classification is an essential task in modern communications, which is used in a wide range of applications, such as network resource allocation, QoS (Quality of Service), malicious detection, etc. With the continuous evolution of network technology, approaches used to classify network encrypted traffic have become increasingly complex, and model training relies heavily on a large amount of labeled data. However, the acquisition of correct and massive labeled data of network traffic in the real environment remains a major challenge in this field. On the opposite, unlabeled traffic is extremely easy to obtain in a network. Therefore, the effective use of unlabeled data is of great significance to the development of modern communications. In this paper, we propose the Sauce model, which can effectively use unlabeled information to obtain high-quality clustering space. It is composed of Aux (auxiliary network) and AE (auto encoder), where Aux is designed for collaborative training with AE, affecting the distribution of samples in the latent space generated by AE. Sauce uses t-SNE (t- distributed stochastic neighbor embedding) to perform secondary dimensionality reduction on the latent code, and then uses a clustering algorithm for cluster analysis. Besides, sauce applies the self-training technique, replacing the real labeled data with pseudo-labeled data to reduce the reliance on labeled data and improve the utilization of unannotated data. We conduct experiments on two real network datasets. The experiments show that Sauce can achieve clustering accuracies of 98.4% (VPN dataset) and 98.0% (TOR dataset), outperforming other unsupervised or semi-supervised learning methods.