Encrypted Malicious Traffic Detection Based on Stacking and Multi-Feature Fusion

HUO Yuehua,ZHAO Faqi
DOI: https://doi.org/10.19678/j.issn.1000-3428.0064805
2023-01-01
Abstract:Although encryption technology protects network communications,plenty malware uses encryption protocols to hide malicious behavior. For the existing Transport Layer Security(TLS) encrypted malicious traffic detection techniques based on machine learning,a single model detection algorithm is available for multi-granularity features,poor applicability,and a high false alarm rate of mixed traffic detection problems. A non-decryption TLS-encrypted malicious traffic detection method based on Stacking strategy and multi-feature fusion is proposed. The multigranularity of encrypted malicious traffic features is analyzed to extract the flow features,connection features,and TLS handshake features of the traffic.The extracted features are statutorily processed using feature engineering to reduce computational overhead. The Random Forest(RF),XGBoost,and Gaussian Naive Bayesian(GNB) classifier models are built for the three classes of features after statute processing to learn the hidden patterns inside them. Using the multidimensional features processed via stream fingerprint fusion,three classifier models are combined using a Stacking strategy to form DMMFC detection model to identify TLSencrypted malicious traffic in the network. The performance of the constructed model is evaluated on the CTU-13 public dataset. The experimental results show that the identification recall of the proposed method is dimensionality of 99.93% in binary classification experiments and a False Alarm Rate(FAR) is less than 0.10% in malicious traffic detection. In can effectively detect non-decrypted TLS encrypted malicious traffic.
What problem does this paper attempt to address?