Encrypted VPN traffic presents an enormous challenge for abnormal traffic detection. This makes traditional payload inspection techniques ineffective. In this research we propose a deep learning based abnormal traffic detection pipeline utilizing a cu...
Encrypted VPN traffic presents an enormous challenge for abnormal traffic detection. This makes traditional payload inspection techniques ineffective. In this research we propose a deep learning based abnormal traffic detection pipeline utilizing a custom dataset constructed in an encrypted VPN environment.
Four deep learning model architectures of CNN, LSTM, GRU and Hybrid were designed, implemented, trained and evaluated on the dataset of packet level metadata and behavioral features. The performance of the models was evaluated using accuracy, precision, recall and F1-score metrics. The obtained results indicated that the hybrid model achieved the highest performance while GRU model achieved the least performance. This study highlights the potential of leveraging well designed custom datasets and deep learning towards enhancing abnormal traffic detection mechanisms in encrypted VPN environments there by preserving privacy in network security applications.