Certificate-Based Transport Layer Security Encrypted Malicious Traffic Detection in Real-Time Network Environments

Yiran Suo, Jingfeng Xue*, Wenjie Guo, Wenbiao Du, Weijie Han*, Chang Xu

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Encryption technology has become ubiquitous in network communication and encrypted malicious traffic detection becomes an important part of malware detection and cyber attack detection. Existing machine learning models and deep learning models are mainly trained based on packet length sequence information and time series information. Recent studies have shown that these models perform poorly in real network environments. In response to this challenge, this paper proposes a novel malicious traffic detection method based on certificate information extracted during the TLS (Transport Layer Security) encrypted handshake protocol. Our approach demonstrates that certificate information exhibits a strong correlation with the maliciousness of traffic, while remaining unaffected by the complexities of the real network environment. The experimental results illustrate that our method has high accuracy and low time overheading.

Original languageEnglish
Title of host publicationAlgorithms and Architectures for Parallel Processing - 24th International Conference, ICA3PP 2024, Proceedings
EditorsTianqing Zhu, Jin Li, Aniello Castiglione
PublisherSpringer Science and Business Media Deutschland GmbH
Pages341-350
Number of pages10
ISBN (Print)9789819615247
DOIs
Publication statusPublished - 2025
Event24th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2024 - Macau, China
Duration: 29 Oct 202431 Oct 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume15251 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference24th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2024
Country/TerritoryChina
CityMacau
Period29/10/2431/10/24

Keywords

  • Certificate
  • Encrypted Malicious Traffic Detection
  • TLS

Fingerprint

Dive into the research topics of 'Certificate-Based Transport Layer Security Encrypted Malicious Traffic Detection in Real-Time Network Environments'. Together they form a unique fingerprint.

Cite this