Shedding Light in the Tunnel: Counting Flows in Encrypted Network Traffic
Fares Meghdouri, Félix Iglesias, Tanja Zseby
Abstract
Fares Meghdouri, Félix Iglesias, Tanja Zseby
Abstract
Network traffic analysis helps experts to under-stand the behavior of communication networks. By exploiting information from packet headers and payloads, ML has been also widely applied to extend the capabilities of traditional statistical approaches. However, modern traffic encryption hampers network traffic analysis, especially in the case of VPNs when multiple flows are encrypted and transported concurrently. An initial step toward extracting information from encrypted traffic is to discover the number of flows that coexist in an aggregated and encrypted data stream. In this paper we propose a technique for disclosing the number of flows aggregated and sent together via encrypted tunnels. We use LSTM cells to learn the relation between the number of flows and the different temporal combinations from available attributes regardless of encryption. Results indicate that predicting the number of flows in encrypted tunnels with a relatively small error is surprisingly possible, providing the basis for a wide range of future research.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Network traffic analysis helps experts to under-stand the behavior of communication networks. By exploiting information from packet headers and payloads, ML has been also widely applied to extend the capabilities of traditional statistical approaches. However, modern traffic encryption hampers network traffic analysis, especially in the case of VPNs when multiple flows are encrypted and transported concurrently. An initial step toward extracting information from encrypted traffic is to discover the number of flows that coexist in an aggregated and encrypted data stream. In this paper we propose a technique for disclosing the number of flows aggregated and sent together via encrypted tunnels. We use LSTM cells to learn the relation between the number of flows and the different temporal combinations from available attributes regardless of encryption. Results indicate that predicting the number of flows in encrypted tunnels with a relatively small error is surprisingly possible, providing the basis for a wide range of future research.
Key concepts: Encryption, Computer science, Deep packet inspection, Network packet, Computer network, Traffic classification, Traffic analysis, Range (aeronautics)