On the Performance of Deep Learning Methods for Identifying Abnormal Encrypted Proxy Traffic

Hongce Zhao, Shunliang Zhang, Zhuang Qiao, Xianjin Huang, Xiaohui Zhang · 2022

Encrypted proxies, such as Shadowsocks and v2ray, are increasingly used to protect user privacy and circumvent censorship. However, the encryption proxies used by some projects may be subject to configuration error or adversary attack makes the encryption ineffective. The resulted abnormal proxy traffic may expose the user’s real network behavior, resulting in user privacy or confidential information leakage. Meanwhile, it is important for network security regulators to identify specific user behaviors from normal encrypted proxy traffics. However, little effort has been put on fingerprinting the encryption validity of proxy traffic. To this end, we employ several typical deep learning methods including Long Short-Term Memory(LSTM), Convolutional Neural Network (CNN) and CNN-LSTM to identify proxy traffic, and investigate the performance and the impact of the sample sizes to these methods. A dataset including normal and abnormal proxy traffic from real network environments is generated to evaluate the performance. Extensive experimental results demonstrate that the mentioned deep learning methods can identify abnormal encrypted proxy traffic with the accuracy up to 99.77%. Moreover, LSTM outperform other DL methods on indentifying the specific user behaviors of normal encrypted proxy traffic.

Read the paper · More papers on PaperTik