CoMDet: A Contrastive Multimodal Pre-Training Approach to Encrypted Malicious Traffic Detection
Jiakun Sun, Xiaotian Zhang, Yabo Wang, Shuyuan Jin · 2024
Encrypted malicious traffic detection aims at iden-tifying malicious activities without decrypting network traffic, which is essential for cybersecurity. Existing methods have shown effective performance in encrypted malicious traffic detection, but their heavy reliance on labeled datasets presents a chal-lenge. This paper presents CoMDet, a contrastive multimodal pre-training approach, to detect encrypted malicious traffic. CoMDet leverages three independent Transformer encoders to learn multimodal feature representations from encrypted traffic based on unlabeled data in the pre-training phase. Meanwhile, we introduce a novel inter-modal contrastive learning method to enhance feature representation by maximizing the mutual information among the modalities. Subsequently, we fine-tune the pre-trained model using limited labeled data. Experimental results demonstrate that CoMDet outperforms the existing semi- supervised learning methods and achieves comparable performance with existing supervised learning methods. It obtains an average ACC of 92% and an average macro-Fl of 86% with only 80 labeled samples in each malicious category. We conduct an investigation on the fine-tuning dataset size and discover that as the dataset size increases, the performance of CoMDet is increasingly comparable to existing supervised learning methods.