Multi-Task Detection and Classification of Encrypted Traffic Sequences via Session2Token Embedding
Rattachement africain : kr. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
The widespread adoption and advancement of encryption protocols have significantly reduced the visibility of network traffic. Consequently, a range of deep learning-based malicious traffic classification studies have actively employed input units such as packets, bursts, and sessions for detection and classification tasks. However, these conventional input formats suffer from performance degradation in encrypted environments, where data becomes randomized and attack traffic grows increasingly complex. In particular, analysis based solely on individual sessions faces fundamental limitations in capturing the sequential nature of attacks and the relational context between malicious sessions. To address these challenges, this study proposes a novel approach that constructs session sequences resembling real-world attack scenarios through a Traffic Sequence Generator and introduces a Session2Token Embedding method to represent each session as a fixed-length token. The proposed model leverages the generated session sequences as input to jointly perform multi-tasks: detecting the presence of malicious traffic within the sequence, classifying the type of attack, predicting the starting position of the first malicious session, and identifying the malicious or benign nature of each session within the sequence. Experimental results demonstrate that the model achieves high accuracy across all tasks, recording $99.8 \%$, $92.4 \%$, $97.1 \%$, and $99.9 \%$, respectively. This work represents the first attempt to learn and utilize the inter-session relationships in encrypted traffic, offering strong potential for practical deployment in real-world malicious traffic detection and classification systems.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Multi-Task Detection and Classification of Encrypted Traffic Sequences via Session2Token Embedding
- Date Crossref
- 22/09/2025
- Éditeur
- IEEE
- Type
- proceedings-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Où se fait cette recherche
-
Korea University pays non établi dans la noticeUniversité ou école supérieure
-
Electronics and Telecommunications Research Institute pays non établi dans la noticeStructure de recherche
Korea University et Electronics and Telecommunications Research Institute.
Une affiliation ne permet pas de déduire la nationalité d’un auteur.