A Method for Robust and Explainable Image-Based Network Traffic Classification with Deep Learning

Amine Hattak, Giacomo Iadarola, Fabio Martinelli, Francesco Mercaldo, Francesco Mercaldo, Antonella Santone

2023

Abstract

In light of the growing reliance on digital technology, the security of digital devices and networks has become a critical concern in the information technology industry. Network analysis can be helpful for identifying and mitigating network-based attacks, as it enables the monitoring of network behavior and the detection of anomalous activity. Through the use of network analysis, organizations can better defend against potential security threats and protect their interconnected digital systems. In this paper, we investigate the use of deep learning techniques for network traffic classification. A robust and explainable deep learning-based approach for traffic classification is proposed starting from raw traffic data represented in PCAP format. This latter will be transformed into visualized images, which are then used as input for deep-learning models in order to discriminate malicious activities. We evaluate the effectiveness of the proposed method, by evaluating two datasets composed of 34389 network traces belonging to 35 categories: 25 related to different malware families and the remaining 10 categories belonging to trusted applications, reaching an accuracy equal to 96.8%. Moreover, we provide reasoning about model evaluation and the correctness of the models by taking into account a prediction explainability based on the visualization of the images generated from the network trace, of the areas symptomatic of a certain prediction.

Download


Paper Citation


in Harvard Style

Hattak A., Iadarola G., Martinelli F., Mercaldo F. and Santone A. (2023). A Method for Robust and Explainable Image-Based Network Traffic Classification with Deep Learning. In Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT; ISBN 978-989-758-666-8, SciTePress, pages 385-393. DOI: 10.5220/0012083200003555


in Bibtex Style

@conference{secrypt23,
author={Amine Hattak and Giacomo Iadarola and Fabio Martinelli and Francesco Mercaldo and Antonella Santone},
title={A Method for Robust and Explainable Image-Based Network Traffic Classification with Deep Learning},
booktitle={Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT},
year={2023},
pages={385-393},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012083200003555},
isbn={978-989-758-666-8},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT
TI - A Method for Robust and Explainable Image-Based Network Traffic Classification with Deep Learning
SN - 978-989-758-666-8
AU - Hattak A.
AU - Iadarola G.
AU - Martinelli F.
AU - Mercaldo F.
AU - Santone A.
PY - 2023
SP - 385
EP - 393
DO - 10.5220/0012083200003555
PB - SciTePress