RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    평균 기반 플로우스펙트럼 보정 기법을 활용한 암호화 트래픽 분류 모델 개선

    한글로보기

    https://www.riss.kr/link?id=T17413564

    • 저자
    • 발행사항

      경산 : 영남대학교 대학원, 2026

    • 학위논문사항

      학위논문(석사) -- 영남대학교 대학원 , 컴퓨터공학과 , 2026. 2

    • 발행연도

      2026

    • 작성언어

      한국어

    • 주제어
    • KDC

      050 판사항(6)

    • 발행국(도시)

      경상북도

    • 기타서명

      Improving encrypted traffic classificaion models using mean-based flowspectrum correction techniques

    • 형태사항

      56 p. : 삽화, 도표 ; 26 cm

    • 일반주기명

      영남대학교 논문은 저작권에 의해 보호받습니다.
      지도교수: 윤종희

    • UCI식별코드

      I804:47017-200000966727

    • 소장기관
      • 영남대학교 도서관 소장기관정보
    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The rapid adoption of Transport Layer Security (TLS) 1.3 and emerging encrypted protocols such as QUIC has dramatically increased the proportion of encrypted network traffic, making traditional Deep Packet Inspection (DPI) techniques infeasible. As a result, classification approaches relying on non-payload information—particularly header-level statistical features and flow-level dynamics—have become essential. FlowSpectrum (FS), which transforms flow characteristics into a compact visual-quantitative representation, has shown competitive performance in encrypted traffic classification tasks.
    However, the original FS formulation exhibits structural instability and high sensitivity to variance in packet sequences, primarily due to flow-level randomness and protocol-induced variability. These factors often cause overlapping spectral patterns between classes and lead to unstable similarity calculations, ultimately degrading the performance of downstream deep learning models.
    To address these limitations, this study proposes the Mean FlowSpectrum (Mean FS) technique, an average-based correction method that integrates a mean-derived adjustment term into the similarity computation. By reflecting the central tendency of each class spectrum, the proposed correction stabilizes the global flow distribution and alleviates the effects of noisy or isolated spectral values. We incorporate the Mean FS representation into Semi-AE and Semi-2DCAE architectures for encrypted traffic classification.
    Experimental evaluations on three datasets—ISCX-VPN2016, USTC-TFC2016, and a real-world TLS 1.3/SSH dataset—demonstrate that the Mean FS-enhanced models significantly outperform conventional FS in terms of Accuracy and F1-score. Notably, in practical environments such as our TLS 1.3/SSH dataset, Mean FS achieved superior performance even compared to YaTC, a state-of-the-art self-supervised representation-learning model. These results confirm that the proposed Mean FS technique effectively resolves structural weaknesses in FlowSpectrum and provides a more robust foundation for encrypted traffic classification in modern network environments.
    번역하기

    The rapid adoption of Transport Layer Security (TLS) 1.3 and emerging encrypted protocols such as QUIC has dramatically increased the proportion of encrypted network traffic, making traditional Deep Packet Inspection (DPI) techniques infeasible. As a ...

    The rapid adoption of Transport Layer Security (TLS) 1.3 and emerging encrypted protocols such as QUIC has dramatically increased the proportion of encrypted network traffic, making traditional Deep Packet Inspection (DPI) techniques infeasible. As a result, classification approaches relying on non-payload information—particularly header-level statistical features and flow-level dynamics—have become essential. FlowSpectrum (FS), which transforms flow characteristics into a compact visual-quantitative representation, has shown competitive performance in encrypted traffic classification tasks.
    However, the original FS formulation exhibits structural instability and high sensitivity to variance in packet sequences, primarily due to flow-level randomness and protocol-induced variability. These factors often cause overlapping spectral patterns between classes and lead to unstable similarity calculations, ultimately degrading the performance of downstream deep learning models.
    To address these limitations, this study proposes the Mean FlowSpectrum (Mean FS) technique, an average-based correction method that integrates a mean-derived adjustment term into the similarity computation. By reflecting the central tendency of each class spectrum, the proposed correction stabilizes the global flow distribution and alleviates the effects of noisy or isolated spectral values. We incorporate the Mean FS representation into Semi-AE and Semi-2DCAE architectures for encrypted traffic classification.
    Experimental evaluations on three datasets—ISCX-VPN2016, USTC-TFC2016, and a real-world TLS 1.3/SSH dataset—demonstrate that the Mean FS-enhanced models significantly outperform conventional FS in terms of Accuracy and F1-score. Notably, in practical environments such as our TLS 1.3/SSH dataset, Mean FS achieved superior performance even compared to YaTC, a state-of-the-art self-supervised representation-learning model. These results confirm that the proposed Mean FS technique effectively resolves structural weaknesses in FlowSpectrum and provides a more robust foundation for encrypted traffic classification in modern network environments.

    더보기

    목차 (Table of Contents)

    • 1. 서론 12
    • 2. 배경지식 및 관련 연구 15
    • 2.1 암호화 트래픽 환경과 특징 15
    • 2.2 전통적 트래픽 분류 기법 17
    • 2.3 머신러닝 기반 트래픽 분류 기법 19
    • 1. 서론 12
    • 2. 배경지식 및 관련 연구 15
    • 2.1 암호화 트래픽 환경과 특징 15
    • 2.2 전통적 트래픽 분류 기법 17
    • 2.3 머신러닝 기반 트래픽 분류 기법 19
    • 2.4 딥러닝 기반 트래픽 분류 기법 21
    • 2.5 플로우스펙트럼 기반 트래픽 분류 기법 23
    • 2.6 데이터 전처리와 특징 선택 26
    • 3. 평균 기반 플로우스펙트럼 보정 기법 28
    • 3.1 기존 플로우스펙트럼 기법의 한계 29
    • 3.2 평균 기반 플로우스펙트럼 보정 기법 31
    • 3.3 전처리 및 입력 크기 축소 34
    • 3.3.1 SII 제거 34
    • 3.3.2 12-tuple 헤더 기반 통계 특징 35
    • 3.3.3 입력 크기 축소 37
    • 4. 실험 및 성능 평가 39
    • 4.1 실험 환경 39
    • 4.2 실험 결과 및 분석 42
    • 4.2.1 SII 제거에 따른 성능 분석 42
    • 4.2.2 보정계수  변화에 따른 성능 분석 45
    • 4.2.3 입력 크기 축소에 따른 성능 및 자원 사용 분석 47
    • 4.2.4 기존 모델과의 성능 비교 49
    • 5. 결론 58
    • 참고문헌 60
    • 영문요약 65
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼