In light of the growing reliance on digital technology, the security of digital devices and networks has become a critical concern in the information technology industry. Network analysis can be helpful for identifying and mitigating network-based attacks, as it enables the monitoring of network behavior and the detection of anomalous activity. Through the use of network analysis, organizations can better defend against potential security threats and protect their interconnected digital systems. In this paper, we investigate the use of deep learning techniques for network traffic classification. A robust and explainable deep learning-based approach for traffic classification is proposed starting from raw traffic data represented in PCAP format. This latter will be transformed into visualized images, which are then used as input for deep-learning models in order to discriminate malicious activities. We evaluate the effectiveness of the proposed method, by evaluating two datasets composed of 34389 network traces belonging to 35 categories: 25 related to different malware families and the remaining 10 categories belonging to trusted applications, reaching an accuracy equal to 96.8%. Moreover, we provide reasoning about model evaluation and the correctness of the models by taking into account a prediction explainability based on the visualization of the images generated from the network trace, of the areas symptomatic of a certain prediction.

A Method for Robust and Explainable Image-Based Network Traffic Classification with Deep Learning

Mercaldo F.;Santone A.
2023-01-01

Abstract

In light of the growing reliance on digital technology, the security of digital devices and networks has become a critical concern in the information technology industry. Network analysis can be helpful for identifying and mitigating network-based attacks, as it enables the monitoring of network behavior and the detection of anomalous activity. Through the use of network analysis, organizations can better defend against potential security threats and protect their interconnected digital systems. In this paper, we investigate the use of deep learning techniques for network traffic classification. A robust and explainable deep learning-based approach for traffic classification is proposed starting from raw traffic data represented in PCAP format. This latter will be transformed into visualized images, which are then used as input for deep-learning models in order to discriminate malicious activities. We evaluate the effectiveness of the proposed method, by evaluating two datasets composed of 34389 network traces belonging to 35 categories: 25 related to different malware families and the remaining 10 categories belonging to trusted applications, reaching an accuracy equal to 96.8%. Moreover, we provide reasoning about model evaluation and the correctness of the models by taking into account a prediction explainability based on the visualization of the images generated from the network trace, of the areas symptomatic of a certain prediction.
2023
978-989-758-666-8
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11695/128086
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 3
  • ???jsp.display-item.citation.isi??? 0
social impact