Malicious encrypted traffic detection based on Bert and one-dimensional CNN model

Pengkai Kang · 2023

With the continuous iteration of network technology, the proportion of encrypted traffic in network traffic is increasing, encrypting traffic can help protect users' personal privacy and data security,but it also enhances the concealment of malicious traffic, making it more difficult to detect. In response to the shortcomings of traditional malicious traffic detection relying on rule databases and the insufficient feature performance of existing malicious traffic detection, this paper proposes a malicious traffic detection model based on pre-trained Bert combined with one-dimensional CNN. The model has two parts: the first part is feature extraction of the Bert model, which inputs a large amount of unlabeled traffic dataset into the Bert model to capture the implicit contextual relationships in large-scale unlabeled traffic; the second part is traffic recognition of the CNN model, which inputs a small labeled dataset into the CNN model after training with the Bert model, to detect malicious encrypted traffic, and finally uses a softmax classifier for binary and multi-classification. Experimental verification is conducted on public datasets, and in binary classification, the accuracy of identifying encrypted malicious traffic is improved to 99.97%, Compared with existing research, there is a significant improvement in F1-score for the Virut and Zeus categories.

Read the paper · More papers on PaperTik