Packet Bytes-Based Abnormal Encrypted Proxy Traffic Identification
Shunliang Zhang, Hongce Zhao, Zuwei Fan · 2024
With the increasing concern about the leakage of user privacy, encryption proxies have been widely used by Internet service providers as a means to protect users' privacy. Unfortunately, users may suffer from ineffective encryption provided by certain proxies due to configuration errors or malicious attacks under abnormal situations. The abnormal proxy traffic could potentially reveal the user's actual network activity, consequently leading to the unauthorized leakage of sensitive information or user privacy. Meanwhile, specific user behaviors should be identified from normal encrypted proxy traffic through network security regulators. However, little work has been done to identify the fine-grained user behaviors found in encrypted proxy traffic and validate its effectiveness. To identify the encrypted proxy traffic, this paper uses a text Convolutional Neural Network that is based on packet bytes. To assess the performance of the packet bytes-based textCNN, we collected encrypted proxy traffic from a real-world environment to create a dataset. The results of our experiments show that the proposed approach is successful in identifying abnormal proxy traffic and outperforms several other benchmark deep learning methods in terms of fine-grain identification of user behaviors.