| 注册
首页|期刊导航|信息安全研究|融合多模态特征的恶意TLS流量检测方法

融合多模态特征的恶意TLS流量检测方法

曾庆鹏 贺述明 柴江力

信息安全研究2025,Vol.11Issue(2):130-138,9.
信息安全研究2025,Vol.11Issue(2):130-138,9.DOI:10.12379/j.issn.2096-1057.2025.02.05

融合多模态特征的恶意TLS流量检测方法

A Malicious TLS Traffic Detection Method with Multi-modal Features

曾庆鹏 1贺述明 1柴江力1

作者信息

  • 1. 南昌大学数学与计算机学院 南昌 330031
  • 折叠

摘要

Abstract

The malicious TLS traffic detection aims to identify network traffic that involves malicious activities transmitted through the TLS protocol.Due to the encryption properties of the TLS protocol,traditional text-based traffic analysis methods have limited effectiveness when dealing with encrypted traffic.To address this issue,a malicious TLS traffic detection method called Multi-Modal Feature Fusion for TLS Traffic Detection(MTBRL)has been proposed.This method extracts and fuses features from different modalities to detect malicious TLS traffic.Firstly,expert knowledge is employed for feature engineering,extracting key features from encrypted traffic,including protocol versions,encryption suites,and certificate information.These features are processed and transformed into two-dimensional image representations.Then,ResNet is utilized to encode these images and extract their features.Simultaneously,an encrypted traffic pre-trained BERT model is used to encode TLS flows,allowing the learning of contextual and semantic features of the TLS traffic.Additionally,an LSTM model is employed to encode the sequence of packet length distributions of the encrypted traffic,capturing temporal characteristics.Finally,through feature fusion techniques,the different modality features are integrated,and the model's weight parameters are automatically learned and optimized using the backpropagation algorithm to accurately predict malicious TLS traffic.Experimental results demonstrate that this method achieves accuracy,precision,recall,and F1-score of 94.94%,94.85%,94.15%,and 94.45%,on the DataCon2020 dataset.This performance is significantly superior to traditional machine learning and deep learning methods.

关键词

加密流量/网络安全/入侵检测/多模态/深度学习

Key words

encrypted traffic/network security/intrusion detection/multi-modal/deep learning

分类

信息技术与安全科学

引用本文复制引用

曾庆鹏,贺述明,柴江力..融合多模态特征的恶意TLS流量检测方法[J].信息安全研究,2025,11(2):130-138,9.

信息安全研究

OA北大核心

2096-1057

访问量0
|
下载量0
段落导航相关论文