Traffic signature code refers to the distinctive fields within network traffic that differentiate it from other applications and facilitate application identification. Its extraction serves as the foundation for application layer security protection, user behavior analysis, intrusion detection, etc., playing an important role in network traffic analysis and network security. Traditional traffic feature code extraction methods employ pattern mining algorithms to mine frequently occurring feature code strings in data traffic, which can only extract part of the continuous feature code, there still exists the issue of discontinuous feature code extraction being missing, alongside redundancy in the extracted feature codes due to overwriting. Based on this, we propose an automatic traffic feature code extraction method called Auto-TFCE in this paper. Firstly, the similarity of application sessions is measured by Levenstein ratio, and a hierarchical clustering algorithm is used to cluster the traffic to obtain single-application traffic. Subsequently, the traffic features are mined using closed frequent pattern mining algorithm, which takes into account the offsets between discontinuous sequences and extracts the continuous and discontinuous feature codes of the application traffic to form a feature code database. Finally, the feature codes extracted by this paper’s method is applied to the firewall application recognition system for experiments. The experimental results show that the accuracy of application identification is improved by 10.8% when feature codes extracted by TFCE algorithm is applied to the firewall application identification control system.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Auto-TFCE: Automatic Traffic Feature Code Extraction Method and Its Application in Cyber Security

  • Junjiang He,
  • Jiayan Wang,
  • Jiangchuan Chen,
  • Wenbo Fang,
  • Lei Zhang,
  • Tao Li

摘要

Traffic signature code refers to the distinctive fields within network traffic that differentiate it from other applications and facilitate application identification. Its extraction serves as the foundation for application layer security protection, user behavior analysis, intrusion detection, etc., playing an important role in network traffic analysis and network security. Traditional traffic feature code extraction methods employ pattern mining algorithms to mine frequently occurring feature code strings in data traffic, which can only extract part of the continuous feature code, there still exists the issue of discontinuous feature code extraction being missing, alongside redundancy in the extracted feature codes due to overwriting. Based on this, we propose an automatic traffic feature code extraction method called Auto-TFCE in this paper. Firstly, the similarity of application sessions is measured by Levenstein ratio, and a hierarchical clustering algorithm is used to cluster the traffic to obtain single-application traffic. Subsequently, the traffic features are mined using closed frequent pattern mining algorithm, which takes into account the offsets between discontinuous sequences and extracts the continuous and discontinuous feature codes of the application traffic to form a feature code database. Finally, the feature codes extracted by this paper’s method is applied to the firewall application recognition system for experiments. The experimental results show that the accuracy of application identification is improved by 10.8% when feature codes extracted by TFCE algorithm is applied to the firewall application identification control system.