A Generalizable Approach for Network Flow Image Representation for Deep Learning
Stefan Machmeier, Manuel Trageser, Marcus Buchwald, Vincent Heuveline · 2023
Detecting network traffic anomalies by transforming traffic into a new image representation has received considerable scientific attention. This transformation allows researchers to apply representation learning to extract valuable information from the sheer volume of network packets. This shift can be explained by the great classification results of convolutional neural networks (CNNs) on image classification tasks. We propose a generalizable approach for network flow image representation to detect patterns without performing any network flow cut-offs. Further, we introduce a novel method to preprocess network traffic to enhance our resulting models. In this step, we remove network protocol header information hindering the models' generalizability. We use a data set containing malware and benign classes and train different deep learning architectures VGG-19, ResNet-50, and ResNeXt-50. ResNet-50 reaches up to 99.48% for multiclass classification accuracy with a macro F1 score of 98.88% and a Kappa score of 99.39% on our preprocessed data set. In the binary scenario, ResNet-50 and VGG-19 achieve 100% accuracy. By this, we show that classifying benign and malicious activities by converting network traffic flows to a quadratic image representation without cut-offs gives promising results.