Symmetry (Nov 2022)

Adversarial Malicious Encrypted Traffic Detection Based on Refined Session Analysis

  • Minghui Li,
  • Zhendong Wu,
  • Keming Chen,
  • Wenhai Wang

DOI
https://doi.org/10.3390/sym14112329
Journal volume & issue
Vol. 14, no. 11
p. 2329

Abstract

Read online

The detection of malicious encrypted traffic is an important part of modern network security research. The producers of the current malware do not pay attention to the fact that malicious encrypted traffic can also be detected; they do not construct further adversarial malicious encrypted traffic to deceive existing malicious encrypted traffic detection methods. However, with the increasing confrontation between attack and defense, adversarial malicious encrypted traffic samples will appear gradually, which will make the existing malicious encrypted traffic detection methods obsolete. In this paper, an adversarial malicious encrypted traffic detection method based on refined session analysis (ADRSA) is proposed. The key ideas of this method are: (1) interpretability analysis is used to extract malicious traffic features that are not easily affected by encryption, (2) restoration technology is used to further improve traffic separability, and (3) a deep neural network is used to identify adversarial malicious encrypted traffic. In experimental tests, the ADRSA method could accurately detect malicious encrypted traffic, particularly adversarial malicious encrypted traffic, and the detection rate is more than 95%. However, the detection rate of other malicious encrypted traffic detection methods is almost zero when facing adversarial malicious encrypted traffic. The detection performance of ADRSA exceeds that of the most popular detection methods.

Keywords