Tor network traffic classification using machine learning based on time-related feature
Mustafa A. Al-Fayoumi, A. Elayyan, A. Odeh, Q. A. Al-Haija · IET conference proceedings. · 2023
Application-level defensive security controls like Intrusion Detection and Prevention Systems (IDS/IPS) need to have visibility on the application data portion of the processed network packets to classify network traffic based on protocol and application information and then to make a proper decision against the traffic based on the defined policy. This functionality is required to check the different passing data streams against fingerprints that identify different protocols and applications. Fingerprints can be defined based on signatures, rules, and patterns of the protocols and applications or based on behaviors and deviations from a predefined baseline. The Onion Router (Tor) is one of the most powerful techniques to keep the confidentiality of data and the anonymity of user identities. Tor establishes encrypted tunnels over the distributed network, making it hard for traffic detection appliances to recognize the going Tor sessions. This paper aims to enable traffic detection and analysis appliances to recognize Tor traffic depending on time-related only attributes with high accuracy and low latency by proposing a statistical technique for analyzing and extracting features represented in the network packets. The proposed statistical technique is built based on computing the correlations between the features among only time-related attributes and dropping those with the lowest effectiveness and importance in labeling and classifying data instances and then utilizing Machine Learning to recognize Tor traffic.