Skip to main navigation Skip to search Skip to main content

SSL malicious traffic detection based on multi-view features

  • Rui Dai
  • , Chuan Gao
  • , Bo Lang
  • , Lixia Yang
  • , Hongyu Liu
  • , Shaojie Chen
  • Beihang University
  • National Computer Network Emergency Response Technical Team

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In recent years, as more and more softwares use SSL encryption protocol to improve the security and integrity of communications, the encrypted traffic is growing, which brings new challenges to cyber attack detection. Since most of the SSL traffic is unreadable ciphertext, traditional pattern recognition and deep packet inspection are not applicable. In addition, the current machine learning methods are not fully applicable to encrypted traffic detection. The detection of encrypted malicious traffic is still an open problem. In this paper, we propose an SSL malicious traffic detection method based on multi-view features. Our method comprehensively extracts features from multiple views, including flow statistics, SSL handshake field, and certificate to retain key original information. We test four machine learning models, i.e., SVM, Decision Tree, Random Forest, and XGBoost on the CTU Malware dataset. The results show that XGBoost performs best reaching an accuracy of 97.71%, which is better than other studies on the CTU dataset.

Original languageEnglish
Title of host publicationICCNS 2019 - 2019 9th International Conference on Communication and Network Security
PublisherAssociation for Computing Machinery
Pages40-46
Number of pages7
ISBN (Electronic)9781450376624
DOIs
StatePublished - 15 Nov 2019
Event9th International Conference on Communication and Network Security, ICCNS 2019 - Chongqing, China
Duration: 15 Nov 201917 Nov 2019

Publication series

NameACM International Conference Proceeding Series

Conference

Conference9th International Conference on Communication and Network Security, ICCNS 2019
Country/TerritoryChina
CityChongqing
Period15/11/1917/11/19

Keywords

  • Feature selection
  • Machine learning
  • Multi-view features
  • SSL malicious traffic detection

Fingerprint

Dive into the research topics of 'SSL malicious traffic detection based on multi-view features'. Together they form a unique fingerprint.

Cite this