A combined-CNN model of TLS Traffic Recognition and Classification
At a glance
- Citations
- 1
- References
- 10
- Comments
- 0
Abstract
The recognition and classification of network application protocol is the premise to implement network traffic engineering, security detection, access control, etc. However, the popularization of TLS (Transport Layer Security) marks the arrival of the era of traffic encryption, and the recognition and classification of network application protocol become a great challenge. This paper compares various existing technologies, analyzes their relevant era background and technical limitations in detail, and at last puts forward a combined-CNN model of TLS Traffic Recognition and Classification. The model generates a one-dimensional input from the session pcap files directly and generates a two-dimensional input by extracting the payload of IP packets related to the key negotiation aiming to achieve a context correlation ability. Finally, the two independent inputs are fused in the full connection layer. The experiment shows that the combined-CNN model performs well, especially in the precision of the recognition and classification of the network application protocol encrypted by TLS.
Publication details
- DOI
- 10.1109/dsc55868.2022.00074
- OpenAlex
- W4312298190
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.