conference-paper

Towards Aggregated Features: A Novel Proxy Detection Method Using NetFlow Data

Research footprint

At a glance

Citations
3
References
22
Comments
0
Paper overview

Öz

Proxies can provide privacy and anonymity protection for users, but can also be exploited by attackers to hide their malicious behaviors. In order to strengthen the monitoring and management of network, proxy detection has become an urgent and challenging task. Although a great deal of efforts has been made for proxy detection, existing methods mostly rely on the packet-level features of a single flow, such as packet inter-arrival time and payload size. In addition, handling the raw traffic throughout the communication process may lead to user privacy leakage to a certain extent. Considering the use of multi-flow statistics and reducing the invasion of user privacy, in this paper, we propose a machine learning based approach for proxy detection with NetFlow data, which only contains session-level statistical information. We extract features through NetFlow data aggregation to build machine learning model and verify the performances on different combinations of features to get the optimal feature sets. Furthermore, the importance of appropriate time windows and minimum flow numbers of NetFlow data aggregation are demonstrated by comprehensive experiments. Based on the real-world datasets, our detection method can distinguish proxy and normal traffic accurately, and achieve about 96% True Positive Rate(TPR) in our experiments with random forest classifier.

Record transparency

Publication details

DOI
10.1109/hpcc-smartcity-dss50907.2020.00050
OpenAlex
W3157405646
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.