详细信息

Deep-Forest-Based Encrypted Malicious Traffic Detection  ( SCI-EXPANDED收录)  

文献类型:期刊文献

英文题名:Deep-Forest-Based Encrypted Malicious Traffic Detection

作者:Zhang, Xueqin[1];Zhao, Min[1];Wang, Jiyuan[1];Li, Shuang[2,3];Zhou, Yue[3];Zhu, Shinan[1]

机构:[1]East China Univ Sci & Technol, Coll Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China;[3]Shanghai Key Lab Comp Software Evaluating & Testi, Shanghai 201112, Peoples R China

年份:2022

卷号:11

期号:7

外文期刊名:ELECTRONICS

收录:;WOS:【SCI-EXPANDED(收录号:WOS:000781119800001)】;

语种:英文

外文关键词:network intrusion detection; encrypted malicious traffic; SSL/TLS; deep forest

摘要:The SSL/TLS protocol is widely used in data encryption transmission. Aiming at the problem of detecting SSL/TLS-encrypted malicious traffic with small-scale and unbalanced training data, a deep-forest-based detection method called DF-IDS is proposed in this paper. According to the characteristics of SSL/TSL protocol, the network traffic was split into sessions according to the 5-tuple information. Each session was then transformed into a two-dimensional traffic image as the input of a deep-learning classifier. In order to avoid information loss and improve the detection efficiency, the multi-grained cascade forest (gcForest) framework was simplified with only cascade structure, which was named cascade forest (CaForest). By integrating random forest and extra trees in the CaForest framework, an end-to-end high-precision detector for small-scale and unbalanced SSL/TSL encrypted malicious traffic was realized. Compared with other deep-learning-based methods, the experimental results showed that the detection rate of DF-IDS was 6.87% to 29.5% higher than that of other methods on a small-scale and unbalanced dataset. The advantage of DF-IDS was more obvious in the multi-classification case.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心