跳到主要导航 跳到搜索 跳到主要内容

TrafCL: Robust Encrypted Malicious Traffic Detection via Contrastive Learning

  • Xiaodu Yang
  • , Sijie Ruan*
  • , Jinyu Li
  • , Yinliang Yue
  • , Bo Sun*
  • *此作品的通讯作者
  • CAS - Institute of Information Engineering
  • Beijing Institute of Technology
  • Zhongguancun Laboratory
  • National Computer Network Emergency Response Technical Team

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Remote control malwares enable cyber attackers to achieve command and control over victim hosts, which are widely employed in ransomware attacks and espionage operations, jeopardizing personal privacy and state security. To effectively detect such malicious traffics holds high practical value. However, prior works have not adequately addressed the task due to challenges of encrypted traffics with misleading contents, incomplete sessions, and limited labels. To overcome these limitations, in this paper, we propose TrafCL, a contrastive learning framework for robust encrypted malicious traffic detection. In TrafCL, we first generate incomplete variants for the input session by Session Augmentation, then extract explicit session features with excluding misleading traffic contents by Triple-aspect Session Feature Extraction, and obtain session representations by Co-attention Session Encoder which fuses triple-aspect session features with capturing their interdependence. After that, we use a projection head to obtain final representations. TrafCL is pre-trained using unlabeled data to learn close representations for complete sessions and their incomplete variants, then fine-tuned on labeled data to detect encrypted malicious traffics. Experiment results show that TrafCL outperforms the best baseline by 11.35% and 6.71% in F1-scores on two datasets respectively.

源语言英语
主期刊名CIKM 2024 - Proceedings of the 33rd ACM International Conference on Information and Knowledge Management
出版商Association for Computing Machinery
2910-2919
页数10
ISBN(电子版)9798400704369
DOI
出版状态已出版 - 21 10月 2024
活动33rd ACM International Conference on Information and Knowledge Management, CIKM 2024 - Boise, 美国
期限: 21 10月 202425 10月 2024

出版系列

姓名International Conference on Information and Knowledge Management, Proceedings
ISSN(印刷版)2155-0751

会议

会议33rd ACM International Conference on Information and Knowledge Management, CIKM 2024
国家/地区美国
Boise
时期21/10/2425/10/24

学术指纹

探究 'TrafCL: Robust Encrypted Malicious Traffic Detection via Contrastive Learning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此