4.5 Article

When a RF beats a CNN and GRU, together-A comparison of deep learning and classical machine learning approaches for encrypted malware traffic classification

期刊

COMPUTERS & SECURITY
卷 124, 期 -, 页码 -

出版社

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2022.103000

关键词

Encrypted traffic classification; Malware detection; Malware classification; Machine learning; Deep learning

向作者/读者索取更多资源

Internet traffic classification is important for QoE, QoS, intrusion detection, and traffic-trend analyses. Although there is no guarantee that DL-based solutions outperform ML-based ones, DL-based models have become the common default. This paper compares well-known DL-based and ML-based models and shows that, in the case of malicious traffic classification, state-of-the-art DL-based solutions do not necessarily outperform classical ML-based ones.
Internet traffic classification plays a crucial role in Quality of Experience (QoE), Quality of Services (QoS), intrusion detection, and traffic-trend analyses. While there is no theoretical guarantee that deep learning (DL)-based solutions perform better than classic machine learning (ML)-based ones, DL-based models have become the common default. This paper compares well-known DL-based and ML-based models and shows that in the case of malicious traffic classification, state-of-the-art DL-based solutions do not necessarily outperform the classical ML-based ones. We exemplify this finding using two well-known datasets for a varied set of tasks, such as: malware detection, malware family classification, detection of zero-day attacks, and classification of an iteratively growing dataset. Note that, it is not feasible to evaluate all possible models to make a concrete statement, thus the above finding is not a recommendation to avoid DL-based models, but rather an empirical finding that in some cases, there are more simplistic solutions, that may perform even better.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据