Journal on Communications ›› 2022, Vol. 43 ›› Issue (10): 12-25.doi: 10.11959/j.issn.1000-436x.2022180

• Papers • Previous Articles     Next Articles

Method based on contrastive learning for fine-grained unknown malicious traffic classification

Yifeng WANG1, Yuanbo GUO1, Qingli CHEN1, Chen FANG1, Renhao LIN2   

  1. 1 Department of Cryptogram Engineering, Information Engineering University, Zhengzhou 450001, China
    2 School of Computer and Artifical Intelligence, Zhengzhou University, Zhengzhou 450001, China
  • Revised:2022-08-29 Online:2022-10-25 Published:2022-10-01
  • Supported by:
    The National Natural Science Foundation of China(61501515)

Abstract:

In order to protect against unknown threats and evasion attacks, a new method based on contrastive learning for fine-grained unknown malicious traffic classification was proposed.Specifically, based on variational auto-encoder (CVAE), it included two classification stages, and cross entropy and reconstruction errors were used for known and unknown traffic classification respectively.Different form other methods, contrastive learning was adopted in different classification stages, which significantly improved the classification performance of the few-shot and unknown (zero-shot) classes.Moreover, some techniques (e.g., re-training and re-sample) combined with contrastive learning further improved the classification performance of the few-shot classes and the generalization ability of model.Experimental results indicate that the proposed method has increased the macro recall of few-shot classes by 20.3% and the recall of unknown attacks by 9.1% respectively, and it also has protected against evasion attacks on partial classes to some extent.

Key words: networA traffic classification, contrastive learning, variational auto-encoder, intrusion detection

CLC Number: 

No Suggested Reading articles found!