conference-paper

A combined-CNN model of TLS Traffic Recognition and Classification

Research footprint

At a glance

Citations
1
References
10
Comments
0
Paper overview

Öz

The recognition and classification of network application protocol is the premise to implement network traffic engineering, security detection, access control, etc. However, the popularization of TLS (Transport Layer Security) marks the arrival of the era of traffic encryption, and the recognition and classification of network application protocol become a great challenge. This paper compares various existing technologies, analyzes their relevant era background and technical limitations in detail, and at last puts forward a combined-CNN model of TLS Traffic Recognition and Classification. The model generates a one-dimensional input from the session pcap files directly and generates a two-dimensional input by extracting the payload of IP packets related to the key negotiation aiming to achieve a context correlation ability. Finally, the two independent inputs are fused in the full connection layer. The experiment shows that the combined-CNN model performs well, especially in the precision of the recognition and classification of the network application protocol encrypted by TLS.

Record transparency

Publication details

DOI
10.1109/dsc55868.2022.00074
OpenAlex
W4312298190
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.