Enhancing Encrypted Traffic Detection for Social Networks With Inter-Packet Contextual Association
Abstract
In social networks, encrypted communication has become increasingly prevalent to protect user privacy. However, this also provides attackers with opportunities to launch covert attacks via encrypted traffic. Traditional traffic detection methods relying on rules and payload analysis fail due to content encryption. As a result, encrypted traffic detection methods based on statistical features and sequence features have gradually emerged as research hotspots. Nevertheless, statistical feature-based methods require access to all packets in a flow, making real-time detection challenging. Therefore, this article exploits sequential features and combines the attention mechanism with sequence prediction to model contextual dependencies among packets. This design allows the model to capture effective flow representations using only a small number of packets, thus helping the classifier achieve accurate classification. In addition, an attention optimization mechanism is introduced to improve the reliability of attention vectors, which contributes to the interpretability of model decisions. Experimental results show that the proposed method achieves competitive classification performance on five datasets using no more than 20 packets, which reduces latency for real-time threat detection. Notably, when using only the first five packets, the average waiting time is only 0.12 s, accounting for merely 0.05% to 3.58% of that required by comparison methods.