Payload-Based Network Traffic Analysis for Application Classification and Intrusion Detection
Süleyman Özdel, Çağatay Ateş, Pelin Damla Ateş, Mutlu Koca, Emin Anarım · 2022 30th European Signal Processing Conference (EUSIPCO) · 2022
Network traffic characterization has become an important topic with the development of evasion techniques. Preventing malicious activities is vital in terms of network performance. On the other hand, defining which applications are run through the network traffic has become a significant issue with the diversification of applications. In this work, a payload-based flow analysis tool that provides both application classification and intrusion detection is proposed. Payload features that characterize network flows efficiently are used to classify network traffic and detect malicious attacks. Application classification performance analysis is performed on a publicly available up-to-date dataset containing traces from most popular applications such as Spotify, WhatsApp, etc. Attack detection performance is evaluated on IDS 2012 and IDS 2017 datasets containing different kinds of attack traces.