About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II

Research Article

MVTBA: A Novel Hybrid Deep Learning Model for Encrypted Malicious Traffic Identification

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-64954-7_4,
        author={Zuwei Fan and Shunliang Zhang},
        title={MVTBA: A Novel Hybrid Deep Learning Model for Encrypted Malicious Traffic Identification},
        proceedings={Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II},
        proceedings_a={SECURECOMM PART 2},
        year={2024},
        month={10},
        keywords={Encrypted malicious traffic Fine-grained identification Deep learning},
        doi={10.1007/978-3-031-64954-7_4}
    }
    
  • Zuwei Fan
    Shunliang Zhang
    Year: 2024
    MVTBA: A Novel Hybrid Deep Learning Model for Encrypted Malicious Traffic Identification
    SECURECOMM PART 2
    Springer
    DOI: 10.1007/978-3-031-64954-7_4
Zuwei Fan1, Shunliang Zhang1,*
  • 1: Institute of Information Engineering
*Contact email: zhangshunliang@iie.ac.cn

Abstract

Encryption technology protects data security and user privacy, but attackers can misuse it to evade detection techniques. To detect encrypted malicious traffic, deep learning based approaches attract increasing interest due to the manual feature engineering of conventional machine learning based methods. However, existing deep learning based approaches suffer from insufficient traffic representation, especially in fine-grained identification. To this end, this paper proposes a hybrid deep learning model MVTBA that can achieve remarkable traffic representation by automatically extracting spatial-temporal features without decryption. MVTBA consists of two sub-networks: MViT and BiLSTM-Att. The local-global spatial features are extracted by MViT through convolutions and an Unfold-Transformer-Fold structure of the mobile vision transformer block. The temporal features are extracted by BiLSTM with Attention to representing the timing dependence between traffic bytes. Subsequently, the two separated feature vectors are fused with an optimal weight factor to obtain the temporal-spatial features, which are fed into the classifier for encrypted malicious traffic identification. Extensive experimental results show that the accuracy of MVTBA in binary classification is improved to 99.99%. Moreover, MVTBA significantly outperforms other benchmark deep learning methods in fine-grained malicious identification, especially in the context of small data samples.

Keywords
Encrypted malicious traffic Fine-grained identification Deep learning
Published
2024-10-15
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-031-64954-7_4
Copyright © 2023–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL