Encrypted Malicious Traffic Detection Based on Sample Selection Optimization and Data Augmentation

Rui Liang, Hanchong Zhang, Fuqiang Liu, Jinyun Zhang, Zhe Sun, Yanfei Song, Chao Li, Liang Zhang · 2024

A large number of network services and applications now use encryption technology to ensure network information security. However, while encryption technology protects user privacy, it also presents new challenges. Traditional traffic detection methods rely on payloads and cannot effectively detect encrypted traffic, thereby providing opportunities for malicious behavior. Detecting encrypted malicious traffic through machine learning or deep learning has become a research hotspot, but there are still some shortcomings: Using the aforementioned artificial intelligence technologies for detection requires a large amount of data for training. In real network environments, the collected datasets have an imbalance between malicious traffic and benign traffic, which severely affects the detection performance of classification models. This paper proposes a method of sample selection optimization and data augmentation to improve the imbalance problem. The roulette wheel selection algorithm is applied to the field of encrypted malicious traffic detection. This algorithm is used only for real malicious samples, assigning different selection probabilities to malicious samples based on sample characteristics. The optimized selected samples are then placed into an improved GAN model named Filtered Auxiliary Classifier GAN (FAC-GAN) for data augmentation. Finally, the balanced dataset is put into a Random Forest (RF) classifier for detection. Experimental results show that the proposed method can generate high-quality samples and its detection performance on the CIC-IDS2017 dataset is superior to existing data augmentation methods.

Read the paper · More papers on PaperTik