Network Traffic Classification based on Single Flow Time Series Analysis
Network traffic monitoring using IP flows is used to handle the current challenge of analyzing encrypted network communication. Nevertheless, the packet aggregation into flow records naturally causes information loss; therefore, this paper proposes a novel flow extension for traffic features based on the time series analysis of the Single Flow Time series, i.e., a time series created by the number of bytes in each packet and its timestamp. We propose 69 universal features based on the statistical analysis of data points, time domain analysis, packet distribution within the flow timespan, time series behavior, and frequency domain analysis. We have demonstrated the usability and universality of the proposed feature vector for various network traffic classification tasks using 15 well-known publicly available datasets. Our evaluation shows that the novel feature vector achieves classification performance similar or better than related works on both binary and multiclass classification tasks. In more than half of the evaluated tasks, the classification performance increased by up to 5\%.
Code (1)
Tasks
ClassificationTime SeriesTime Series AnalysisTraffic ClassificationSimilar Papers 제목 키워드 기반
On the LRD of the Aggregated Traffic Flows in High-Speed Computer Networks
This paper studies and analyses the behavior of the Long-Range Dependence in network traffic after classifying traffic flows in aggregated time series. Following Differentiated Services architecture principles, the gener…
Time SeriesTime Series AnalysisOn the LRD of the Aggregated Traffic Flows in High-Speed Computer Networks
This paper studies and analyses the behavior of the Long-Range Dependence in network traffic after classifying traffic flows in aggregated time series. Following Differentiated Services architecture principles, the gener…
Time SeriesTime Series AnalysisNetTiSA: Extended IP Flow with Time-series Features for Universal Bandwidth-constrained High-speed Network Traffic Classification
Network traffic monitoring based on IP Flows is a standard monitoring approach that can be deployed to various network infrastructures, even the large IPS-based networks connecting millions of people. Since flow records …
Time SeriesTraffic ClassificationDeepTrend: A Deep Hierarchical Neural Network for Traffic Flow Prediction
In this paper, we consider the temporal pattern in traffic flow time series, and implement a deep learning model for traffic flow prediction. Detrending based methods decompose original flow series into trend and residua…
PredictionTime SeriesTime Series AnalysisImproving Internet Traffic Matrix Prediction via Time Series Clustering
We present a novel framework that leverages time series clustering to improve internet traffic matrix (TM) prediction using deep learning (DL) models. Traffic flows within a TM often exhibit diverse temporal behaviors, w…
Time Series Clustering