20212021 International Conference on Data Mining Workshops (ICDMW)Requires access

Shedding Light in the Tunnel: Counting Flows in Encrypted Network Traffic

Fares Meghdouri, Félix Iglesias, Tanja Zseby

Open publisher page 2 citations

Abstract

Network traffic analysis helps experts to under-stand the behavior of communication networks. By exploiting information from packet headers and payloads, ML has been also widely applied to extend the capabilities of traditional statistical approaches. However, modern traffic encryption hampers network traffic analysis, especially in the case of VPNs when multiple flows are encrypted and transported concurrently. An initial step toward extracting information from encrypted traffic is to discover the number of flows that coexist in an aggregated and encrypted data stream. In this paper we propose a technique for disclosing the number of flows aggregated and sent together via encrypted tunnels. We use LSTM cells to learn the relation between the number of flows and the different temporal combinations from available attributes regardless of encryption. Results indicate that predicting the number of flows in encrypted tunnels with a relatively small error is surprisingly possible, providing the basis for a wide range of future research.

About this research paper

What this paper is about

Network traffic analysis helps experts to under-stand the behavior of communication networks. By exploiting information from packet headers and payloads, ML has been also widely applied to extend the capabilities of traditional statistical approaches. However, modern traffic encryption hampers network traffic analysis, especially in the case of VPNs when multiple flows are encrypted and transported concurrently. An initial step toward extracting information from encrypted traffic is to discover the number of flows that coexist in an aggregated and encrypted data stream. In this paper we propose a technique for disclosing the number of flows aggregated and sent together via encrypted tunnels. We use LSTM cells to learn the relation between the number of flows and the different temporal combinations from available attributes regardless of encryption. Results indicate that predicting the number of flows in encrypted tunnels with a relatively small error is surprisingly possible, providing the basis for a wide range of future research.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Network traffic analysis helps experts to under-stand the behavior of communication networks. By exploiting information from packet headers and payloads, ML has been also widely applied to extend the capabilities of traditional statistical approaches. However, modern traffic encryption hampers network traffic analysis, especially in the case of VPNs when multiple flows are encrypted and transported concurrently. An initial step toward extracting information from encrypted traffic is to discover the number of flows that coexist in an aggregated and encrypted data stream. In this paper we propose a technique for disclosing the number of flows aggregated and sent together via encrypted tunnels. We use LSTM cells to learn the relation between the number of flows and the different temporal combinations from available attributes regardless of encryption. Results indicate that predicting the number of flows in encrypted tunnels with a relatively small error is surprisingly possible, providing the basis for a wide range of future research.

Key concepts: Encryption, Computer science, Deep packet inspection, Network packet, Computer network, Traffic classification, Traffic analysis, Range (aeronautics)

Related papers

Back to paper searchBrowse research topicsOriginal source
Shedding Light in the Tunnel: Counting Flows in Encrypted Network Traffic — Research Paper | ScholarLens