Unidirectional Encrypted Traffic Classification: A Survey

Chen Yang,Zheyuan Gu,Yuhao Wei,Gang Xiong,Gaopeng Gou,Shan Yao,Yang Yu
DOI: https://doi.org/10.1109/ipec61310.2024.00125
2024-01-01
Abstract:Techniques for classifying encrypted traffic typically rely on learning the interaction patterns between communicating parties to determine the traffic category. However, with the widespread application of asymmetric routing mechanisms and link load balancing, a large volume of network equipment cannot observe the complete bidirectional traffic, posing challenges to the deployment of existing methods. In order to solve this problem, research into unidirectional encrypted traffic classification methods has gradually emerged. In this paper, we provide a comprehensive survey of existing unidirectional encrypted traffic classification methods and showcase the latest research progress in this field. Based on how to resolve the contradiction between unidirectional traffic data and model reliance on bidirectional interaction features, we categorize existing methods into three main types: 1) unidirectional feature separation-based methods, 2) unidirectional feature mining-based methods, and 3) pairwise feature prediction-based methods. This paper details the characteristics of each method and discusses their advantages and disadvantages. We hope our work will draw researchers’ attention to the real-world network environment, thereby better promoting the development of the encrypted traffic classification field.
What problem does this paper attempt to address?