ANALYSIS OF ENCRYPTED NETWORK TRAFFIC BASED ON ENTROPY CALCULATION AND APPLICATION OF NEURAL NETWORK CLASSIFIERS
Abstract
Network traffic analysis allows you to solve many problems, such as: determining the pattern of data transmission over the network, collecting statistics on the use of web applications, monitoring and further researching network load, identifying potential malicious software and network attacks, etc. 40% of Internet traffic belongs to unknown applications. This suggests that for the area of network traffic analysis, the task of classifying applications has acquired particular importance. Improvements in software in the field of network technologies have contributed to the discovery of serious vulnerabilities in the implementation of some network protocols, namely TCP and HTTP. By using network traffic analyzers, an attacker gained access to the contents of data packets transmitted over the network. However, with the increasing qualifications of the information community in the field of computer security, as well as with the development of network technology standards, the analysis of network traffic has become noticeably more complicated. The increased use of mathematical methods for protecting information, such as symmetric and asymmetric cryptographic protocols, has led to the fact that most approaches to the analysis of network traffic have lost their meaning and are no longer used. Therefore, the search for new solutions to the problem of classifying network traffic, taking into account the possibility of its encryption, is relevant. The article is devoted to the description of a new mixed approach to the analysis of network traffic, based on the combined use of information theory and machine learning algorithms. It also provides a comparative analysis of the proposed method with existing approaches based on both information theory and machine learning. The aim of the research is to develop an algorithm based on an intelligent approach to the analysis of network traffic. The proposed algorithm is based on calculating entropy and using neural network classifiers. Research objectives include: theoretical substantiation of the proposed approach in the field of information theory, as well as machine learning algorithms; carrying out a structural description of the implemented algorithms for calculating entropy and classifying applications that generate encrypted traffic; comparative analysis of the proposed algorithm with existing approaches to the analysis of encrypted network traffic. The result of the research is a new algorithm that allows classifying various types of encrypted traffic with a high degree of reliability.








