Network traffic classification is crucial for network management, security monitoring, and ensuring quality of service. However, classifying traffic from Decentralized Applications (DApps) is challenging due to their similar encryption configurations on the same blockchain platform, making their traffic patterns indistinguishable. Traditional classification methods, such as Deep Packet Inspection, struggle with encrypted traffic. Similarly, existing machine learning methods, like Random Forest (RF), fail to effectively capture the unique traffic patterns of DApps. To address these challenges, this paper proposes a novel multimodal classification approach that combines Graph Neural Networks (GNN) and Bidirectional Encoder Representations from Transformers (BERT) to classify DApp traffic. This method leverages GNN and BERT to extract and analyze interaction patterns and payload information from network traffic, using self-attention mechanisms to fuse these features, providing a comprehensive feature representation. We collected traffic data from 100 commonly used DApps on the Ethereum platform to create a high-quality dataset. Experimental results on this dataset demonstrate that our model achieves 90.96% accuracy in DApp classification, with a precision of 92.04%, recall of 90.14%, and an F1-score of 91.08%, outperforming unimodal approaches and other advanced techniques in accuracy and robustness. Additionally, the method was tested on public datasets, achieving 86.31% accuracy on the ISCX-Tor dataset and 96.58% accuracy on the Bot-IoT dataset. By combining GNN and BERT, our approach effectively addresses the challenges of encrypted DApp traffic classification, providing a robust solution for network management and security monitoring.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Analyzing Decentralized Applications Traffic: A Multimodal Approach Based on GNN and BERT

  • Haoyang Lu,
  • Rui Zhang,
  • Tong Kong

摘要

Network traffic classification is crucial for network management, security monitoring, and ensuring quality of service. However, classifying traffic from Decentralized Applications (DApps) is challenging due to their similar encryption configurations on the same blockchain platform, making their traffic patterns indistinguishable. Traditional classification methods, such as Deep Packet Inspection, struggle with encrypted traffic. Similarly, existing machine learning methods, like Random Forest (RF), fail to effectively capture the unique traffic patterns of DApps. To address these challenges, this paper proposes a novel multimodal classification approach that combines Graph Neural Networks (GNN) and Bidirectional Encoder Representations from Transformers (BERT) to classify DApp traffic. This method leverages GNN and BERT to extract and analyze interaction patterns and payload information from network traffic, using self-attention mechanisms to fuse these features, providing a comprehensive feature representation. We collected traffic data from 100 commonly used DApps on the Ethereum platform to create a high-quality dataset. Experimental results on this dataset demonstrate that our model achieves 90.96% accuracy in DApp classification, with a precision of 92.04%, recall of 90.14%, and an F1-score of 91.08%, outperforming unimodal approaches and other advanced techniques in accuracy and robustness. Additionally, the method was tested on public datasets, achieving 86.31% accuracy on the ISCX-Tor dataset and 96.58% accuracy on the Bot-IoT dataset. By combining GNN and BERT, our approach effectively addresses the challenges of encrypted DApp traffic classification, providing a robust solution for network management and security monitoring.