vix.ing · top · new · best · stats · spec

Adversarial Network Traffic: Towards Evaluating the Robustness of Deep\n Learning-Based Network Traffic Classification

2020/03/02 by Amir Mahdi Sadeghzadeh, Sadeghzadeh, Amir Mahdi, Saeed Shiravi +3 · 1 citation
Computer Science · #Cryptography and Security (cs.CR) #Digital Media Forensic Detection #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.2003.01261

openalex publication_date 2020/03/02 · openalex created_date 2022/07/26 · openalex updated_date 2026/07/28

Abstract

Network traffic classification is used in various applications such as\nnetwork traffic management, policy enforcement, and intrusion detection\nsystems. Although most applications encrypt their network traffic and some of\nthem dynamically change their port numbers, Machine Learning (ML) and\nespecially Deep Learning (DL)-based classifiers have shown impressive\nperformance in network traffic classification. In this paper, we evaluate the\nrobustness of DL-based network traffic classifiers against Adversarial Network\nTraffic (ANT). ANT causes DL-based network traffic classifiers to predict\nincorrectly using Universal Adversarial Perturbation (UAP) generating methods.\nSince there is no need to buffer network traffic before sending ANT, it is\ngenerated live. We partition the input space of the DL-based network traffic\nclassification into three categories: packet classification, flow content\nclassification, and flow time series classification. To generate ANT, we\npropose three new attacks injecting UAP into network traffic. AdvPad attack\ninjects a UAP into the content of packets to evaluate the robustness of packet\nclassifiers. AdvPay attack injects a UAP into the payload of a dummy packet to\nevaluate the robustness of flow content classifiers. AdvBurst attack injects a\nspecific number of dummy packets with crafted statistical features based on a\nUAP into a selected burst of a flow to evaluate the robustness of flow time\nseries classifiers. The results indicate injecting a little UAP into network\ntraffic, highly decreases the performance of DL-based network traffic\nclassifiers in all categories.\n

Cited by

Related