Malware Network Traffic Classification on the Edge

Malware Network Traffic Classification on the Edge
复制标题

DOI:
10.1109/mass56207.2022.00118
复制
发表时间:
2022-10
期刊:
2022 IEEE 19th International Conference on Mobile Ad Hoc and Smart Systems (MASS)
影响因子:
--
通讯作者:
Eric R. Chen;A. Perez-Pons
Eric R. Chen;A. Perez-Pons
中科院分区:
其他
文献类型:
--
作者:
Eric R. Chen;A. Perez-Pons

文献摘要

被引文献

相似文献

网络流量分类是许多网络安全应用的一部分,例如入侵检测系统和异常检测。目前,许多网络安全任务采用云计算架构,包括网络流量分类。然而,随着网络数据数量的不断增加,这种架构可能无法满足未来的延迟需求。因此,我们建议利用边缘计算进行网络流量分类,并应用微型机器学习来分类更接近数据源。我们的方法使用TensorFlow Lite将传统的卷积神经网络转换为在边缘设备上运行的微型机器学习模型。为了评估边缘分类的影响,我们在边缘设备上进行了模拟,并将这些结果与云计算的结果进行了比较。我们确定,与云计算替代方案相比,边缘设备更快,延迟更低,在所有实验中,准确性和模型大小的降低可以忽略不计。
Network traffic classification is a part of many cybersecurity applications, such as intrusion detection systems and anomaly detection. Currently, many cybersecurity tasks employ a cloud computing architecture, including network traffic classification. However, this architecture may not be able to meet the latency demands in the future with the ever-increasing number of network data. Therefore, we propose to perform network traffic classification utilizing edge computing and applying tiny machine learning to classify closer to the data source. Our approach uses TensorFlow Lite to convert a traditional convolutional neural network into a tiny machine learning model that runs on an edge device. In order to assess the impact of edge classification, we ran simulations on the edge device and compared these results to a cloud-computing counterpart. We determined that the edge device was faster and had reduced latency compared to a cloud computing alternative, with a negligible reduction in accuracy and decrease in model size throughout all experiments.