A comprehensive machine learning-based approach for virtual private network traffic detection, classification and hiding
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F60076658%3A12220%2F25%3A43910903" target="_blank" >RIV/60076658:12220/25:43910903 - isvavai.cz</a>
Nalezeny alternativní kódy
RIV/68407700:21240/25:00386158 RIV/60076658:12310/25:43910903
Výsledek na webu
<a href="https://www.sciencedirect.com/science/article/pii/S1389128625004979" target="_blank" >https://www.sciencedirect.com/science/article/pii/S1389128625004979</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1016/j.comnet.2025.111530" target="_blank" >10.1016/j.comnet.2025.111530</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
A comprehensive machine learning-based approach for virtual private network traffic detection, classification and hiding
Popis výsledku v původním jazyce
Virtual private networks (VPNs) are often used today for remote access to corporate networks or to access information resources limited to specific IP ranges or specific geolocations. Reliable detection and classification of normal or encrypted VPN traffic is a non-trivial task that has not yet been reliably solved. In our research, we created a large dataset containing samples of network traffic of different VPN protocols. We used the dataset to build nine machine learning (ML) models and compared their efficiency. Our best ML models can detect VPN network traffic with very high accuracy, subsequently classify the type of VPN protocol, and evaluate the content of traffic transported via the encrypted VPN protocols. To validate the robustness of our models, we invented and applied various VPN traffic detection obfuscation methods whose usage may interfere with network traffic identification and classification. Such methods can also be used to design and implement more secure next-generation VPN protocols that will be potentially not detectable by methods based on ML models.
Název v anglickém jazyce
A comprehensive machine learning-based approach for virtual private network traffic detection, classification and hiding
Popis výsledku anglicky
Virtual private networks (VPNs) are often used today for remote access to corporate networks or to access information resources limited to specific IP ranges or specific geolocations. Reliable detection and classification of normal or encrypted VPN traffic is a non-trivial task that has not yet been reliably solved. In our research, we created a large dataset containing samples of network traffic of different VPN protocols. We used the dataset to build nine machine learning (ML) models and compared their efficiency. Our best ML models can detect VPN network traffic with very high accuracy, subsequently classify the type of VPN protocol, and evaluate the content of traffic transported via the encrypted VPN protocols. To validate the robustness of our models, we invented and applied various VPN traffic detection obfuscation methods whose usage may interfere with network traffic identification and classification. Such methods can also be used to design and implement more secure next-generation VPN protocols that will be potentially not detectable by methods based on ML models.
Klasifikace
Druh
J<sub>imp</sub> - Článek v periodiku v databázi Web of Science
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název periodika
Computer Networks
ISSN
1389-1286
e-ISSN
1872-7069
Svazek periodika
neuveden
Číslo periodika v rámci svazku
October
Stát vydavatele periodika
NL - Nizozemsko
Počet stran výsledku
15
Strana od-do
1-15
Kód UT WoS článku
001578007500001
EID výsledku v databázi Scopus
2-s2.0-105011078357