Encrypted Malicious Traffic Detection Based on Graph Convolutional Network and Temporal Dissection

Yuchen Liu, Shanshan Wang, Jin Au-Yeung, Zhenxiang Chen · 2024

With the rapid development of the Internet, network security issues are receiving increasing attention and various network attack methods are emerging, among which encrypted malicious traffic, as a common attack method, has become a major challenge in the field of network security due to its extremely high concealment and impact. Traditional network security detection methods are difficult to accurately detect and defend against encrypted malicious traffic because they focus more on the detection of traffic content and fail to analyze and detect malicious traffic in terms of the structure and characteristics of the traffic data itself. Therefore, we construct network traffic graphs based on graph convolutional network to classify nodes within the network traffic data. In addition, we introduce temporal dissection to gain a more comprehensive understanding of network micro-dynamics. This study innovatively proposes a method that combines graph convolutional network and temporal dissection for the detection of encrypted malicious traffic. We conduct experiments on two real-world encrypted network traffic datasets, the results show that the accuracy, precision, recall and F1-measure of the method exceed 98% on the USTC-TFC2016 dataset, and detect more than 7900 flows per second, which is nearly 27 times faster than the same detection effect model. The performance on the DataCon2020 dataset is also better than the other six models, confirming that our method can effectively improve the effectiveness and speed of encrypted malicious traffic detection.

Read the paper · More papers on PaperTik