paper-with-me

홈 › Papers

Extensible Machine Learning for Encrypted Network Traffic Application Labeling via Uncertainty Quantification

2022-05-11 · Steven Jorgensen, John Holodnak, Jensen Dempsey, Karla de Souza, Ananditha Raghunath, Vernon Rivet, Noah DeMoes, Andrés Alejos, Allan Wollaber

With the increasing prevalence of encrypted network traffic, cyber security analysts have been turning to machine learning (ML) techniques to elucidate the traffic on their networks. However, ML models can become stale as new traffic emerges that is outside of the distribution of the training set. In order to reliably adapt in this dynamic environment, ML models must additionally provide contextualized uncertainty quantification to their predictions, which has received little attention in the cyber security domain. Uncertainty quantification is necessary both to signal when the model is uncertain about which class to choose in its label assignment and when the traffic is not likely to belong to any pre-trained classes. We present a new, public dataset of network traffic that includes labeled, Virtual Private Network (VPN)-encrypted network traffic generated by 10 applications and corresponding to 5 application categories. We also present an ML framework that is designed to rapidly train with modest data requirements and provide both calibrated, predictive probabilities as well as an interpretable "out-of-distribution" (OOD) score to flag novel traffic samples. We describe calibrating OOD scores using p-values of the relative Mahalanobis distance. We demonstrate that our framework achieves an F1 score of 0.98 on our dataset and that it can extend to an enterprise network by testing the model: (1) on data from similar applications, (2) on dissimilar application traffic from an existing category, and (3) on application traffic from a new category. The model correctly flags uncertain traffic and, upon retraining, accurately incorporates the new data.

📄 PDF Abstract BibTeX arXiv:2205.05628

Code (0)

등록된 구현이 없습니다.

Tasks

BIG-bench Machine LearningUncertainty Quantification

Similar Papers 제목 키워드 기반

Feature Mining for Encrypted Malicious Traffic Detection with Deep Learning and Other Machine Learning Algorithms

2023-04-07 · ZiHao Wang, Vrizlynn L. L. Thing

The popularity of encryption mechanisms poses a great challenge to malicious traffic detection. The reason is traditional detection techniques cannot work without the decryption of encrypted traffic. Currently, research …

Deep Learning

Real-time Traffic Classification for 5G NSA Encrypted Data Flows With Physical Channel Records

2023-07-15 · Xiao Fei, Philippe Martins, Jialiang Lu

The classification of fifth-generation New-Radio (5G-NR) mobile network traffic is an emerging topic in the field of telecommunications. It can be utilized for quality of service (QoS) management and dynamic resource all…

ClassificationManagementTraffic Classification

Video QoE Metrics from Encrypted Traffic: Application-agnostic Methodology

2025-04-20 · Tamir Berger, Jonathan Sterenson, Raz Birman, Ofer Hadar

Instant Messaging-Based Video Call Applications (IMVCAs) and Video Conferencing Applications (VCAs) have become integral to modern communication. Ensuring a high Quality of Experience (QoE) for users in this context is c…

Unsupervised Dataset Cleaning Framework for Encrypted Traffic Classification

2025-08-31 · Kun Qiu, Ying Wang, Baoqian Li, Wenjun Zhu arxiv

Traffic classification, a technique for assigning network flows to predefined categories, has been widely deployed in enterprise and carrier networks. With the massive adoption of mobile devices, encryption is increasing…

Feature Analysis of Encrypted Malicious Traffic

2023-12-06 · Anish Singh Shekhawat, Fabio Di Troia, Mark Stamp

In recent years there has been a dramatic increase in the number of malware attacks that use encrypted HTTP traffic for self-propagation or communication. Antivirus software and firewalls typically will not have access t…