DISTILLER: Encrypted traffic classification via multimodal multitask deep learning

DISTILLER: Encrypted traffic classification via multimodal multitask deep learning
复制标题

DOI:
10.1016/j.jnca.2021.102985
复制
发表时间:
2021-04-16
影响因子:
8.7
通讯作者:
Pescape, Antonio
Pescape, Antonio
中科院分区:
计算机科学2区
文献类型:
--
作者:
Aceto, Giuseppe;Ciuonzo, Domenico;Pescape, Antonio

文献摘要

被引文献

相似文献

流量分类,即从其网络流量中推断应用和/或服务,代表了服务管理的主力和有价值的分析信息的推动者。加密协议的增长趋势和网络流量的快速发展正在淘汰基于有效载荷检测或机器学习的流量分类设计解决方案。相反,深度学习目前被认为是基于自动提取的特征设计流量分类器的可行方法。这些反映了从多方面(加密)流量中提取的复杂模式,这些流量以“多模式”方式隐含地携带信息,并且还可以用于具有多样化网络可见性的应用场景中,用于(同时)处理多个分类任务。为此,本文提出了一种用于流量分类的新型多模式多任务深度学习方法,从而产生了DISTILLER分类器。后者能够利用流量数据的异质性(通过学习模态内和模态间的依赖性),克服现有(短视的)基于单模态深度学习的流量分类建议的性能限制,并同时解决与不同提供商的需求相关的不同流量分类问题。基于加密流量的公共数据集,我们评估了DISTILLER,并与为加密流量分类提出的最先进的深度学习架构(基于单模态哲学)进行了公平比较。结果表明,我们的建议的收益超过单任务基线和本地多任务架构的多任务扩展。
Traffic classification, i.e. the inference of applications and/or services from their network traffic, represents the workhorse for service management and the enabler for valuable profiling information. The growing trend toward encrypted protocols and the fast-evolving nature of network traffic are obsoleting the traffic-classification design solutions based on payload-inspection or machine learning. Conversely, deep learning is currently foreseen as a viable means to design traffic classifiers based on automatically-extracted features. These reflect the complex patterns distilled from the multifaceted (encrypted) traffic, that implicitly carries information in "multimodal" fashion, and can be also used in application scenarios with diversified network visibility for (simultaneously) tackling multiple classification tasks. To this end, in this paper a novel multimodal multitask deep learning approach for traffic classification is proposed, leading to the DISTILLER classifier. The latter is able to capitalize traffic-data heterogeneity (by learning both intra- and inter-modality dependencies), overcome performance limitations of existing (myopic) single-modal deep learning-based traffic classification proposals, and simultaneously solve different traffic categorization problems associated to different providers' desiderata. Based on a public dataset of encrypted traffic, we evaluate DISTILLER in a fair comparison with state-of-the-art deep learning architectures proposed for encrypted traffic classification (and based on single-modality philosophy). Results show the gains of our proposal over both multitask extensions of single-task baselines and native multitask architectures.