Towards Aggregated Features: A Novel Proxy Detection Method Using NetFlow Data
At a glance
- الاستشهادات
- 3
- المراجع
- 22
- Comments
- 0
Abstract
Proxies can provide privacy and anonymity protection for users, but can also be exploited by attackers to hide their malicious behaviors. In order to strengthen the monitoring and management of network, proxy detection has become an urgent and challenging task. Although a great deal of efforts has been made for proxy detection, existing methods mostly rely on the packet-level features of a single flow, such as packet inter-arrival time and payload size. In addition, handling the raw traffic throughout the communication process may lead to user privacy leakage to a certain extent. Considering the use of multi-flow statistics and reducing the invasion of user privacy, in this paper, we propose a machine learning based approach for proxy detection with NetFlow data, which only contains session-level statistical information. We extract features through NetFlow data aggregation to build machine learning model and verify the performances on different combinations of features to get the optimal feature sets. Furthermore, the importance of appropriate time windows and minimum flow numbers of NetFlow data aggregation are demonstrated by comprehensive experiments. Based on the real-world datasets, our detection method can distinguish proxy and normal traffic accurately, and achieve about 96% True Positive Rate(TPR) in our experiments with random forest classifier.
Publication details
- DOI
- 10.1109/hpcc-smartcity-dss50907.2020.00050
- OpenAlex
- W3157405646
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.