EP4674090A1 - System and method of classifying network traffic - Google Patents

System and method of classifying network traffic

Info

Publication number
EP4674090A1
EP4674090A1 EP24763365.4A EP24763365A EP4674090A1 EP 4674090 A1 EP4674090 A1 EP 4674090A1 EP 24763365 A EP24763365 A EP 24763365A EP 4674090 A1 EP4674090 A1 EP 4674090A1
Authority
EP
European Patent Office
Prior art keywords
network traffic
current network
vector
based model
sample
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP24763365.4A
Other languages
German (de)
French (fr)
Inventor
Ran DUBIN
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ariel Scientific Innovations Ltd
Original Assignee
Ariel Scientific Innovations Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ariel Scientific Innovations Ltd filed Critical Ariel Scientific Innovations Ltd
Publication of EP4674090A1 publication Critical patent/EP4674090A1/en
Pending legal-status Critical Current

Links

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N20/00—Machine learning
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N3/00—Computing arrangements based on biological models
    • G06N3/02—Neural networks
    • G06N3/08—Learning methods

Definitions

  • the present invention relates generally to the technological field of computer networking. More specifically, the present invention relates to network traffic monitoring and classification for various purposes, such as malware analysis, quality of experience (QoE) characterization, application classification, application behavior analysis, network usage analysis, troubleshooting network performance etc.
  • QoE quality of experience
  • DPI Deep Packet Inspection
  • Some known solutions apply machine learning (ML) and artificial intelligence (Al) based techniques (e.g., parametric ML-based models) to classify network traffic based on parsed packets, embedded in a predefined feature space.
  • ML machine learning
  • Al artificial intelligence
  • the invention may be directed to a method of classifying network traffic by at least one processor, the method including capturing a current network traffic; sampling the current network traffic, to extract a first sample thereof; calculating a first vector, representing a vector embedding of the first sample in a feature space; applying at least one ML-based model on the first vector to classify the current network traffic by pertinence to at least one class.
  • the invention may be directed to a system for classifying a network traffic, the system including a non-transitory memory device, wherein modules of instruction code are stored, and at least one processor associated with the memory device, and configured to execute the modules of instruction code, whereupon execution of said modules of instruction code, the at least one processor is configured to capture a current network traffic; sample the current network traffic, to extract a first sample thereof; calculate a first vector, representing a vector embedding of the first sample in a feature space; apply at least one machine-learning (ML)-based model on the first vector to classify the current network traffic by pertinence to at least one class.
  • ML machine-learning
  • applying the at least one ML-based model may include applying at least one parametric ML-based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model may be respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
  • applying the nonparametric ML-based model may include calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class. [Oil] In some embodiments, applying the nonparametric ML-based model may further include classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
  • applying the parametric ML-based model may be performed when at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
  • the method may further include, when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sampling the current network traffic, to extract a second sample thereof; calculating a second vector, representing a vector embedding of the second sample in the feature space; concatenating the first vector with the second vector; applying the at least one of ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
  • the samples of previously classified network traffic may be selected from a set of samples of previously classified network traffic, and the method may further include, when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receiving a label, representing pertinence of the at least one class to the current network traffic, and updating the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
  • the method may further include retraining the parametric ML-based model based on the updated set of samples.
  • the feature space may be defined by initial features; and the method may further include generating new features, based on the updated set of samples; and enhancing the feature space by combining the new features with the initial features.
  • applying the parametric ML-based model may further include calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
  • applying the nonparametric ML-based model may be performed when the calculated confidence metric value does not exceed a predefined confidence metric value threshold.
  • the nonparametric ML-based model may be a classification-by-retrieval (CbR) ML-based model.
  • the at least one class may represent a classification of the current network traffic by at least one of: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic;
  • the at least one class may represent a classification of the current network traffic by a type of an application communicating via the current network traffic; the method may further include extracting at least one packet flow within the first sample, associated with a specific application, and calculating the first vector may be performed based on the at least one packet flow.
  • the at least one packet flow may represent a plurality of packet flows
  • the method further include aggregating the plurality of packet flows, and calculating the first vector may be performed based on the aggregated plurality of packet flows.
  • extracting the first sample of the network traffic may be performed by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and
  • said at least one processor may be further configured to apply the at least one ML-based model further by applying at least one parametric ML-based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model may be respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
  • said at least one processor may be further configured to apply the nonparametric ML-based model by calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class.
  • said at least one processor may be further configured to apply the nonparametric ML-based model further by classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
  • said at least one processor may be further configured to apply the parametric ML-based model, provided that at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
  • said at least one processor may be further configured to: when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sample the current network traffic, to extract a second sample thereof; calculate a second vector, representing a vector embedding of the second sample in the feature space; concatenate the first vector with the second vector; and apply the at least one ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
  • said at least one processor may be further configured to: select the samples of previously classified network traffic from a set of samples of previously classified network traffic; when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receive a label, representing pertinence of the at least one class to the current network traffic; and update the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
  • said at least one processor may be further configured to retrain the parametric ML-based model based on the updated set of samples.
  • the feature space may be defined by initial features; and wherein said at least one processor may be further configured to: generate new features, based on the updated set of samples; and enhance the feature space by combining the new features with the initial features.
  • said at least one processor may be further configured to apply the parametric ML-based model further by calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
  • said at least one processor may be further configured to apply the nonparametric ML-based model, provided that the calculated confidence metric value does not exceed a predefined confidence metric value threshold.
  • the at least one class may represent a classification of the current network traffic by a type of an application communicating via the current network traffic; and said at least one processor may be further configured to: extract at least one packet flow within the first sample, associated with a specific application; and calculate the first vector based on the at least one packet flow.
  • the at least one packet flow may represent a plurality of packet flows; and said at least one processor may be further configured to aggregate the plurality of packet flows; and calculate the first vector based on the aggregated plurality of packet flows.
  • said at least one processor may be further configured to extract the first sample of the network traffic by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and (d) detected activity of at least one of nodes communicating via the current network traffic after inactivity.
  • FIG. 1 is a block diagram, depicting a computing device which may be included in a system for classifying network traffic, according to some embodiments;
  • ML-based models may be configured or “trained” for a specific task, e.g., classification.
  • the term “parametric ML-based model” may refer to an ML-based model that is trained to make an assumption according to a specific task using predefined form of a mapping function (mapping input and output values) and a fixed set of parameters thereof. That is, the mapping function and the set of parameters remain the same regardless of the number of training examples used for training. Training a parametric ML-based model for the specific task may involve adjusting the values of these parameters based on examples.
  • Examples of parametric ML-based models may include Logistic Regression, Linear Discriminant Analysis, Perceptron, Naive Bayes, Artificial Neural Networks etc.
  • nonparametric ML-based model may refer to an ML-based model that does not have a predetermined form of the mapping function.
  • nonparametric ML-based models may include k-Nearest Neighbours (and any other approximate-nearest-neighbor-based algorithm), Decision Trees (e.g., CART and C4.5), Support Vector Machines etc.
  • parametric ML-based models may be artificial neural networks (ANN).
  • a neural network (NN) or an artificial neural network (ANN), e.g., a neural network implementing a machine learning (ML) or artificial intelligence (Al) function may refer to an information processing paradigm that may include nodes, referred to as neurons, organized into layers, with links between the neurons. The links may transfer signals between neurons and may be associated with weights.
  • a NN may be configured or trained for a specific task, e.g., pattern recognition or classification. Training a NN for the specific task may involve adjusting these weights based on examples.
  • Each neuron of an intermediate or last layer may receive an input signal, e.g., a weighted sum of output signals from other neurons, and may process the input signal using a linear or nonlinear function (e.g., an activation function).
  • the results of the input and intermediate layers may be transferred to other neurons and the results of the output layer may be provided as the output of the NN.
  • the neurons and links within a NN are represented by mathematical constructs, such as activation functions and matrices of data elements and weights.
  • a processor e.g., CPUs or graphics processing units (GPUs), or a dedicated hardware device may perform the relevant calculations.
  • ML-based model may be a single ML- based model or a set (ensemble) of ML-based models realizing as a whole the same function as a single one.
  • ML-based model may be a single ML- based model or a set (ensemble) of ML-based models realizing as a whole the same function as a single one.
  • embodiments of the present invention may refer to extracting and analyzing samples of the network traffic.
  • sample of the network traffic may represent a sequence of network packets, wherein the sequence may be of various sizes (include various number of packets) and may be taken from different parts of the network traffic within the network communication session.
  • the sequence may be of various sizes (include various number of packets) and may be taken from different parts of the network traffic within the network communication session.
  • distinguishing patterns characterizing the sequence of the network packets and not the separate packets, which may help revealing various attributes of traffic “behavior”.
  • a high efficiency of applying ML-based methods may be achieved, providing sufficient reliability of network traffic classification.
  • some embodiments of the present invention may use a combination of parametric and nonparametric ML-based models.
  • One of the known benefits of using nonparametric ML-based models lies in that they are much more flexible and adaptable to transformations in the input data.
  • one of the common examples of nonparametric ML-based models - nearest neighbor algorithm and other approaches based thereon, like classification-by-retrieval (CbR) - do not require training or retraining at all. These approaches are based on comparing the input with each entry of the training dataset, calculating similarity metric values, and making classification based on the similarity metric values. If needed, the new class or the new representatives of the known class may be added just by supplementing the training dataset with the training examples of the respective class, without any actual retraining of the model.
  • FIG. 1 is a block diagram depicting a computing device, which may be included within an embodiment of the system for predicting cancer metastases location, according to some embodiments.
  • Computing device 1 may include a processor or controller 2 that may be, for example, a central processing unit (CPU) processor, a chip or any suitable computing or computational device, an operating system 3, a memory device 4, instruction code 5, a storage system 6, input devices 7 and output devices 8.
  • processor 2 (or one or more controllers or processors, possibly across multiple units or devices) may be configured to carry out methods described herein, and/or to execute or act as the various modules, units, etc. More than one computing device 1 may be included in, and one or more computing devices 1 may act as the components of, a system according to embodiments of the invention.
  • Operating system 3 may be or may include any code segment (e.g., one similar to instruction code 5 described herein) designed and/or configured to perform tasks involving coordination, scheduling, arbitration, supervising, controlling or otherwise managing operation of computing device 1, for example, scheduling execution of software programs or tasks or enabling software programs or other modules or units to communicate.
  • Operating system 3 may be a commercial operating system. It will be noted that an operating system 3 may be an optional component, e.g., in some embodiments, a system may include a computing device that does not require or include an operating system 3.
  • Memory device 4 may be or may include, for example, a Random-Access Memory (RAM), a read only memory (ROM), a Dynamic RAM (DRAM), a Synchronous DRAM (SD-RAM), a double data rate (DDR) memory chip, a Flash memory, a volatile memory, a non-volatile memory, a cache memory, a buffer, a short-term memory unit, a long-term memory unit, or other suitable memory units or storage units.
  • Memory device 4 may be or may include a plurality of possibly different memory units.
  • Memory device 4 may be a computer or processor non-transitory readable medium, or a computer non-transitory storage medium, e.g., a RAM.
  • a non-transitory storage medium such as memory device 4, a hard disk drive, another storage device, etc. may store instructions or code which when executed by a processor may cause the processor to carry out methods as described herein.
  • Instruction code 5 may be any executable code, e.g., an application, a program, a process, task, or script. Instruction code 5 may be executed by processor or controller 2 possibly under control of operating system 3. For example, instruction code 5 may be a standalone application or an API module that may be configured to calculate prediction of a class to which the traffic pertains, as further described herein. Although, for the sake of clarity, a single item of instruction code 5 is shown in Fig. 1, a system according to some embodiments of the invention may include a plurality of executable code segments or modules similar to instruction code 5 that may be loaded into memory device 4 and cause processor 2 to carry out methods described herein.
  • Storage system 6 may be or may include, for example, a flash memory as known in the art, a memory that is internal to, or embedded in, a micro controller or chip as known in the art, a hard disk drive, a CD-Recordable (CD-R) drive, a Blu-ray disk (BD), a universal serial bus (USB) device or other suitable removable and/or fixed storage unit.
  • Various types of input and output data may be stored in storage system 6 and may be loaded from storage system 6 into memory device 4 where it may be processed by processor or controller 2.
  • memory device 4 may be a non-volatile memory having the storage capacity of storage system 6. Accordingly, although shown as a separate component, storage system 6 may be embedded or included in memory device 4.
  • Input devices 7 may be or may include any suitable input devices, components, or systems, e.g., a detachable keyboard or keypad, a mouse and the like.
  • Output devices 8 may include one or more (possibly detachable) displays or monitors, speakers and/or any other suitable output devices.
  • Any applicable input/output (RO) devices may be connected to Computing device 1 as shown by blocks 7 and 8.
  • NIC network interface card
  • USB universal serial bus
  • any suitable number of input devices 7 and output device 8 may be operatively connected to Computing device 1 as shown by blocks 7 and 8.
  • a system may include components such as, but not limited to, a plurality of central processing units (CPU) or any other suitable multi-purpose or specific processors or controllers (e.g., similar to element 2), a plurality of input units, a plurality of output units, a plurality of memory units, and a plurality of storage units.
  • CPU central processing units
  • controllers e.g., similar to element 2
  • FIGs. 2A and 2B depict system 10 for classifying network traffic and processing module 20 of system 10 for classifying network traffic respectively, according to some embodiments.
  • system 10 may be implemented as a software module, a hardware module, or any combination thereof.
  • system 10 may be or may include a computing device such as element 1 of Fig. 1.
  • system 10 may be adapted to execute one or more modules of instruction code (e.g., element 5 of Fig. 1) to request, receive, analyze, calculate and produce various data.
  • system 10 may be adapted to execute one or more modules of instruction code (e.g., element 5 of Fig. 1) in order to perform steps of the claimed method etc.
  • modules of instruction code e.g., element 5 of Fig. 1
  • arrows may represent flow of one or more data elements to and from system 10 and/or among modules or elements of system 10. Some arrows have been omitted in Figs. 2 A and 2B for the purpose of clarity.
  • system 10 may include preprocessing module 20.
  • preprocessing module 20 may include traffic capturing module 21.
  • Traffic capturing module 21 may be configured to capture current network traffic 10A.
  • capturing when referring to the network traffic (e.g., network traffic 10A), the terms “capturing” and “receiving” shall be considered equivalent. It should also be understood that capturing may be performed either by the node (e.g., computing device 1 shown in Fig. 1) directly participating in the communication via the network traffic (e.g., server or client), or by the node intercepting communication of other nodes.
  • the node e.g., computing device 1 shown in Fig. 1
  • the network traffic e.g., server or client
  • preprocessing module 20 may further include traffic sampling module 22.
  • Traffic sampling module 22 may be configured to receive captured traffic 10A from traffic capturing module 21. Traffic sampling module 22 may be further configured to sample current network traffic 10A, in order to extract samples 22A thereof, e.g., including first sample 22A’.
  • Traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a random distribution of the start point and the end point. In other words, traffic sampling module 22 may randomly select which portion of network traffic 10A to extract.
  • traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic (e.g., network traffic 10A).
  • traffic sampling module 22 may be configured to detect when specific node participating in the communication started and ended transmitting or receiving network traffic 10A and extract the respective portion of network traffic 10A.
  • traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a fixed period defined by the start point and the end point. That is, traffic sampling module 22 may be configured to extract samples of a fixed predefined size.
  • traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on detected activity of at least one of nodes communicating via the current network traffic (e.g., network traffic 10A) after inactivity.
  • traffic sampling module 22 may be configured to detect when specific node participating in the communication switches between active/inactive states and trigger sample extraction accordingly.
  • preprocessing module 20 may further include packet flow extraction module 23. Packet flow extraction module 23 may be configured to receive traffic samples 22A (e.g., first sample 22A’).
  • Packet flow extraction module 23 may be further configured to extract packet flows 23A within samples 22A (e.g., first sample 22A’), associated with a specific application communicating via the current network traffic (e.g., video service, messenger, internet browser, gaming application etc.).
  • samples 22A e.g., first sample 22A’
  • a specific application communicating via the current network traffic (e.g., video service, messenger, internet browser, gaming application etc.).
  • preprocessing module 20 may further include packet flow aggregation module 24.
  • Packet flow aggregation module 24 may be configured to receive packet flows 23 A from packet flow extraction module 23. Packet flow aggregation module 24 may be further configured to aggregate the plurality of packet flows 23A and to output aggregated packet flows 24A.
  • various logic may be applied in order to perform packet flow aggregation.
  • the plurality of packet flows e.g., packet flows 23A
  • preprocessing module 20 may further include embedding module 25.
  • Embedding module 25 may be configured to receive aggregated packet flows 24A (or alternatively each packet flow 23A separately, or entire traffic sample 22A, e.g., first sample 22A’).
  • Embedding module 25 may be further configured to calculate vectors 20A (e.g., first vector 20A’ of first sample 22 A’), each representing a vector embedding of the respective traffic sample 22A (e.g., first sample 22A’) in feature space 25’. Accordingly, in some embodiments, embedding module 25 may be configured to perform calculation of vectors 20A (e.g., first vector 20A’) based on packet flow (e.g., packet flow 23A) or based on aggregated plurality of packet flows (e.g., aggregated packet flows 24A). For example, vector 20A’ may represent a vector embedding of a single packet flow (e.g., packet flow 23A) or aggregated plurality of packet flows (e.g., aggregated packet flows 24A) within first sample 22A’ .
  • vector 20A may represent a vector embedding of a single packet flow (e.g., packet flow 23A) or aggregated plurality of packet flows (e.g., aggregated packet flows 24A
  • the present invention is not limited to any specific features of the feature space used for embedding (e.g., feature space 25’). However, it may be implied herein that the features of the feature space (e.g., feature space 25’) characterize samples of the network traffic (e.g., samples 22A of traffic 10A) as representing the plurality of network packets, rather than each packet individually.
  • such features may represent or be derived from such network traffic data as source ports (or combination of source ports present in the sequence of packets), destination ports (or combination of destination ports present in the sequence of packets), source IP addresses (or combination of source IP addresses present in the sequence of packets), destination IP addresses (or combination of destination IP addresses present in the sequence of packets), protocols (TCP/ UDP) etc.
  • the set of features of the feature space may be formed by applying deep learning clustering techniques on samples of the network traffic (e.g., samples 22A of traffic 10A).
  • the set of features of the feature space may include the features listed in the table below.
  • preprocessing module 20 may be configured to output calculated vectors 20A (e.g., vector 20A’ of first sample 22A’).
  • system 10 may include control module 30, parametric ML-based model 40 and nonparametric ML-based model 50.
  • control module 30 may be configured to apply ML-based models (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the calculated vectors 20A (e.g., vector 20A’) to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., assigned class 40A).
  • ML-based models e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50
  • Parametric ML-based model 40 and nonparametric ML-based model 50 may be configured to classify the current network traffic (e.g., traffic 10A) by pertinence to classes representing: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic; (c) a quality -of-experience (QoE) characteristic of an application communicating via the current network traffic; (d) an active mode of an application communicating via the current network traffic (e.g., video call, audio call, messaging, file transferring etc.).
  • QoE quality -of-experience
  • parametric ML-based model 40 may be respectively pretrained to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., class 40A), based on the vector (e.g., vector 20A) representing a vector embedding of the traffic sample in a feature space (e.g., samples 22 A of traffic 10A in feature space 25’).
  • the vector e.g., vector 20A
  • parametric ML-based model 40 may be pretrained using commonly known supervised ML techniques, based on a training dataset including a plurality of training samples - vectors representing vector embeddings of a plurality of traffic samples in the feature space, said vectors correspondingly associated with a plurality of predefined classes.
  • nonparametric ML-based model 50 may be configured to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., class 40A) based on one or more respectively labeled vectors of samples of previously classified network traffic (e.g., vectors 70A of classified samples).
  • nonparametric ML-based model 50 may be a classification-by-retrieval (CbR) ML-based model or a nearest neighbor classifier.
  • CbR classification-by-retrieval
  • labeled vectors 70A of classified samples may represent a vector embedding of the respective classified samples in the same feature space (e.g., feature space 25’).
  • vectors 70A may be prestored and/or received from a separate database 70 of previously classified network traffic.
  • database 70 may store a set 70A’ of samples of previously classified network traffic (also referred herein as “labeled samples”), from which the samples of previously classified network traffic are selected.
  • embedding module 25 may be further configured to receive labeled samples and to calculate vectors 70A, each representing a vector embedding of the respective classified traffic sample in feature space 25’.
  • labeled may refer herein to “labeled with indication of pertinence to the respective class (e.g., class 40A)”.
  • parametric ML-based model 40 may be respectively pretrained using a training dataset formed based on the same labeled samples of classified network traffic (e.g., using labeled vectors 70A of classified samples), as further used by nonparametric ML-based model 50 to perform classification.
  • parametric ML-based model 40 may be pretrained using a training dataset formed based on labeled samples of classified network traffic, which are completely irrelevant to the labeled samples used by nonparametric ML-based model 50 to perform classification.
  • nonparametric ML-based model 50 may be further configured to calculate similarity metric values 50A’ representing a degree of similarity between (i) the vectors 20A of samples of the current traffic (e.g., first vector 20A’) and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the respective classes (e.g., labeled vectors 70A).
  • nonparametric ML-based model 50 may be further configured to classify the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A), based on the one or more similarity metric values (e.g., similarity metric values 50A’), provided that the one or more similarity metric values (e.g., similarity metric values 50A’) exceed predefined similarity metric value threshold (e.g., similarity metric value threshold 50’).
  • predefined similarity metric value threshold e.g., similarity metric value threshold 50’
  • nonparametric ML-based model 50 may be further configured to evaluate similarity between the received vector (e.g., first vector 20A’) and one or more labeled vectors (e.g., labeled vectors 70A) by calculating respective similarity metric values 50A’.When at least one similarity metric value 50A’ exceeds predefined similarity metric value threshold 50’, it may indicate that vector 20A is sufficiently similar to respective labeled vector 70A.
  • nonparametric ML-based model 50 may be configured to classify the received vector 20A (e.g., first vector 20A’ and, therefore, traffic 10A) by pertinence to the same class as the label of the respective labeled vector (e.g., vector 70A) represents.
  • parametric ML-based model 40 may be further configured to calculate confidence metric value 40A’ representing a confidence of classifying the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A).
  • control module 30 may be configured to apply nonparametric ML-based model 50 when calculated confidence metric value 40 A’ does not exceed predefined confidence metric value threshold 40’ (that is, when parametric ML- based model 50 is not confident enough in assigning any of target classes (e.g., class 40A)).
  • the problem of adjustment of the network traffic classification system to the constantly evolving network traffic is addressed based on the following approach of dealing with OOD (out-of-distribution) network traffic data.
  • OOD out-of-distribution
  • Dramatic drop of classification reliability with respect to samples pertaining to OOD data is a known drawback of parametric ML-based models (e.g., parametric ML-based model 40).
  • OOD data may refer to data which, in the respective feature space (e.g., feature space 25’), is located sufficiently far from the distribution of training data (e.g., training dataset formed based on set 70A’ of samples of previously classified network traffic), that was used for pretraining parametric ML-based model (e.g., parametric ML- based model 40).
  • training data e.g., training dataset formed based on set 70A’ of samples of previously classified network traffic
  • parametric ML-based model e.g., parametric ML- based model 40
  • nonparametric ML-based model 50 may be configured to evaluate whether vector 20A of sample 22A of current network traffic 10A pertains to OOD data.
  • control module 30 may be configured to apply parametric ML-based model 40 only when at least one of one or more similarity metric values 50A’ exceed predefined similarity metric value threshold 50’, which may indicate that the respective vector 20A (e.g., first vector 20A’) does not pertain to OOD data.
  • nonparametric ML- based model 50 may be configured to output OOD indication 10A”.
  • traffic sampling module 22 may be further configured to receive OOD indication 10 A’ ’ .
  • Traffic sampling module 22 may be further configured, upon receiving OOD indication 10A”, sample the current network traffic (e.g., traffic 10A), to extract a second sample thereof (e.g., second sample 22A”).
  • Traffic sampling module 22 may be further configured to transfer the second sample (e.g., second sample 22A”) to embedding module 25.
  • Embedding module 25 may be further configured to calculate a second vector 20A”, representing a vector embedding of the second sample 22 A” in the feature space (e.g., feature space 25’).
  • preprocessing module 20 may be further configured to apply packet flow extraction module 23 and packet flow aggregation module 24 with respect to the second sample (e.g., second sample 22A”), same as it was described with reference to the first sample (e.g., first sample 22A’).
  • embedding module 25 may be configured to perform calculation of second vector 20A’ ’ , based on respective packet flow or based on respective aggregated plurality of packet flows.
  • preprocessing module 20 may further include vector concatenation module 26.
  • Vector concatenation module 26 may be configured to receive plurality of vectors 20A calculated by embedding module 25 (e.g., first vector 20A’ and second vector 20 A”).
  • Vector concatenation module may be further configured to concatenate plurality of vectors 20A (e.g., first vector 20A’ and second vector 20A”) and output concatenated vectors 20 A’ ’ ’ .
  • control module 30 may be further configured to apply the at least one of ML-based model (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the concatenated vectors (e.g., concatenated vectors 20 A’”) to classify the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A).
  • ML-based model e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50
  • the sequence of actions including extracting new sample (e.g., second sample 22A”) of the current network traffic (e.g., traffic 10A), calculating vector of the new sample (e.g., second vector 20A”), concatenating new vector with the previously calculated ones (e.g., second vector 20A” with first vector 20A’), and applying the ML-based models (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) thereon, may be performed iteratively. In some embodiments, this iterative sequence of actions may be performed until the sufficient level of similarity metric value is achieved (e.g., until one or more similarity metric values 50 A’ exceed predefined similarity metric value threshold 50’).
  • this iterative sequence of actions may be performed until the sufficient level of similarity metric value is achieved (e.g., until one or more similarity metric values 50 A’ exceed predefined similarity metric value threshold 50’).
  • system 10 may further include review system 60.
  • system 10 when none of the one or more similarity metric values (e.g., similarity metric values 50A’) exceeds the predefined similarity metric value threshold (e.g., similarity metric value threshold 50’), system 10 may be configured to transmit respective sample or plurality of samples (e.g., samples 22A’ and 22A”) to review system 60.
  • the involvement of review system 60 may be triggered by receiving OOD indication 10A”.
  • Review system 60 may be configured to receive a label (e.g., label 60A), representing pertinence of the at least one class (e.g., class 40A) to the current network traffic (e.g., traffic 10A).
  • review system 60 may be configured to apply various techniques of detailed analysis of the network traffic (e.g., traffic 10A). E.g., review system 60 may apply DPI methods in combination with decryption techniques, to reveal the content of respective packets. In some embodiments, review system 60 may be configured to request and receive label 60A from a third-party deep packet analysis service.
  • review system 60 may be configured to provide respective samples (e.g., samples 22A’ and 22A”) to user interface (UI) module (not shown in figures) for further manual or semi-automatic review, and to receive label 60A via UI module from the user.
  • samples 22A’ and 22A respective samples
  • UI user interface
  • system 10 may be configured to output the result of classification (e.g., classified current network traffic 10A’).
  • the result of classification may represent current network traffic (e.g., traffic 10A) and assigned class (e.g., class 40A) thereto.
  • system 10 is configured to output the result of classification (e.g., classified current network traffic 10 A’) when both similarity metric value (e.g., similarity metric value 50A’) and confidence metric value (e.g., confidence metric value 40A’) exceed the similarity metric value threshold (e.g., similarity metric value threshold 50’) and confidence metric value threshold (e.g., confidence metric value threshold 40’) accordingly.
  • similarity metric value e.g., similarity metric value 50A’
  • confidence metric value threshold e.g., confidence metric value threshold 40’
  • system 10 may be configured to update the set 70A’ of samples by adding the samples of the current network traffic (e.g., first sample 22 A’ and/or second sample 22A” of traffic 10A) classified based on the label (e.g., label 60 A) or in result of classification by parametric and/or nonparametric ML-based models (e.g., parametric ML- based model 40 and nonparametric ML-based model 50) thereto, thereby producing updated set 70A” of samples of previously classified network traffic 10A.
  • the samples of the current network traffic e.g., first sample 22 A’ and/or second sample 22A” of traffic 10A
  • the label e.g., label 60 A
  • parametric and/or nonparametric ML-based models e.g., parametric ML- based model 40 and nonparametric ML-based model 50
  • system 10 may be further configured to retrain the parametric ML-based model (e.g., parametric ML-based model 40) based on the updated set of samples (e.g., updated set 70A”).
  • the parametric ML-based model e.g., parametric ML-based model 40
  • the updated set of samples e.g., updated set 70A.
  • nonparametric ML-based models e.g., nonparametric ML-based model 50
  • no additional actions are required in order to improve performance of nonparametric ML-based model, except for updating the set of samples of previously classified network traffic (e.g., set 70A’).
  • system 10 may constantly adapt to new unknown types of network traffic (e.g., traffic 10A) and provide sufficient reliability of network traffic classification.
  • network traffic constantly evolves - new applications communicating via network traffic and new types of information transmitted via the network arise. Consequently, at some point, traffic may change substantially and it may no longer be enough to update the set of samples of previously classified network traffic (e.g., set 70A’) and to retrain parametric ML-based model (e.g., parametric ML-based model 40) in order to achieve desired classification reliability.
  • Such network traffic may have new features that were not present in previously classified traffic.
  • feature space 25’ may be defined by initial features.
  • embedding module 25 may be further configured to generate new features, based on the updated set of samples (e.g., updated set 70A”), and enhance the feature space (e.g., feature space 25’) by combining the new features with the initial features.
  • embedding module 25 may be further configured to calculate vectors representing vector embeddings of samples of new network traffic in the enhanced feature space 25”.
  • sparse vectors may be used.
  • vectors of samples of “old” traffic may have zero values with respect to new features.
  • detecting samples 22A of network traffic 10A pertaining to OOD data and performing abovementioned actions thereafter (extracting new sample 22 A”, calculating vector 20 A” thereof, concatenating the calculated vector 20 A” with the previous vector 20A’, applying review system 60, updating set 70 A’ of samples, retraining parametric ML- based model 40, enhancing feature space 25’ etc.) contribute to the abovementioned improvement of the network traffic classification.
  • the system may be configured to continuously adapt to new unknown network traffic and reliability of network traffic classification may thus be increased.
  • FIG. 3 a flow diagram is presented, depicting a method of classifying network traffic, by at least one processor, according to some embodiments.
  • the at least one processor may perform capturing of a current network traffic (e.g., current network traffic 10A).
  • Step S1005 may be carried out by traffic capturing module 21 (as described with reference to Fig. 2B).
  • the at least one processor may perform sampling of the current network traffic (e.g., current network traffic 10A), to extract a first sample thereof (e.g., first sample 22A’).
  • Step S1010 may be carried out by traffic sampling module 22 (as described with reference to Fig. 2B).
  • the at least one processor may perform calculating of a first vector (e.g., first vector 20A’), representing a vector embedding of the first sample (e.g., first sample 22A’) in a feature space (e.g., feature space 25’).
  • Step S 1015 may be carried out by embedding module 25 (as described with reference to Fig. 2B).
  • the at least one processor may perform applying of at least one machine-learning (ML)-based model (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the first vector (e.g., first vector 20A’) to classify the current network traffic (e.g., current network traffic 10A) by pertinence to at least one class (e.g., class 40A).
  • ML machine-learning
  • Step S1020 may be carried out by control module 30, parametric ML-based model 40 and nonparametric ML-based model 50 (as described with reference to Fig. 2A).
  • the claimed invention represents the system and method of classifying network traffic which provide an improvement of the technological field of computer networking by increasing reliability of network traffic classification.
  • the claimed invention provides a reliable instrument for classifying encrypted network traffic.
  • the method embodiments described herein are not constrained to a particular order or sequence.
  • all formulas described herein are intended as examples only and other or different formulas may be used. Additionally, some of the described method embodiments or elements thereof may occur or be performed at the same point in time.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • Mathematical Physics (AREA)
  • Artificial Intelligence (AREA)
  • Data Mining & Analysis (AREA)
  • Evolutionary Computation (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Medical Informatics (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Health & Medical Sciences (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Biomedical Technology (AREA)
  • Biophysics (AREA)
  • Computational Linguistics (AREA)
  • General Health & Medical Sciences (AREA)
  • Molecular Biology (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present invention relates to the technological field of computer networking, the invention may be directed to a method of classifying network traffic by at least one processor, the method including capturing a current network traffic; sampling the current network traffic, to extract a first sample thereof; calculating a first vector, representing a vector embedding of the first sample in a feature space; applying at least one ML-based model on the first vector to classify the current network traffic by pertinence to at least one class. The claimed invention provides a reliable instrument for classifying encrypted network traffic.

Description

SYSTEM AND METHOD OF CLASSIFYING NETWORK TRAFFIC
CROSS REFERENCE TO RELATED APPLICATIONS
[001] This application claims the benefit of priority of U.S. Provisional Patent Application No. 63/448,460, filed February 27, 2023, the contents of which are all incorporated herein by reference in their entirety.
FIELD OF THE INVENTION
[002] The present invention relates generally to the technological field of computer networking. More specifically, the present invention relates to network traffic monitoring and classification for various purposes, such as malware analysis, quality of experience (QoE) characterization, application classification, application behavior analysis, network usage analysis, troubleshooting network performance etc.
BACKGROUND OF THE INVENTION
[003] Nowadays, various network traffic monitoring software and hardware solutions known in the art utilize Deep Packet Inspection (DPI) tools to parse network packets in order to inspect the data being sent over a computer network in detail and apply actions thereto, such as alerting, blocking, re-routing, or logging the data accordingly. Some known solutions apply machine learning (ML) and artificial intelligence (Al) based techniques (e.g., parametric ML-based models) to classify network traffic based on parsed packets, embedded in a predefined feature space.
[004] Currently, a major part of the network traffic is encrypted. Encryption significantly complicates ML-based classification and dramatically decreases its reliability, however, it does not involve the entire packet data, certain metadata is transferred nonencrypted (e.g., Domain Name System (DNS) data and Service Name Indicator (SNI)). In such cases, the amount of nonencrypted data may be still enough to reveal specific patterns in traffic for classification purposes.
[005] Due to the rapid technological progress, in the upcoming network standards, the metadata (including DNS and SNI) will be encrypted (e.g., as required by DNS over HTTPS (DOH) protocol). Current DPI methods will no longer provide the ability to reveal the information essential for traffic classification and, consequently, known traffic classification approaches become ineffective. Hence, it creates new problems for intermediate entities connecting servers and clients, including security entities, network enforcement entities, enterprise entities, telecom entities etc.
SUMMARY OF THE INVENTION
[006] Accordingly, there is a need for a system and method of classifying network traffic which would provide an improvement of the technological field of computer networking by increasing reliability of network traffic classification. In particular, there is a need for a reliable instrument for classifying encrypted network traffic.
[007] In the general aspect, the invention may be directed to a method of classifying network traffic by at least one processor, the method including capturing a current network traffic; sampling the current network traffic, to extract a first sample thereof; calculating a first vector, representing a vector embedding of the first sample in a feature space; applying at least one ML-based model on the first vector to classify the current network traffic by pertinence to at least one class.
[008] In another general aspect, the invention may be directed to a system for classifying a network traffic, the system including a non-transitory memory device, wherein modules of instruction code are stored, and at least one processor associated with the memory device, and configured to execute the modules of instruction code, whereupon execution of said modules of instruction code, the at least one processor is configured to capture a current network traffic; sample the current network traffic, to extract a first sample thereof; calculate a first vector, representing a vector embedding of the first sample in a feature space; apply at least one machine-learning (ML)-based model on the first vector to classify the current network traffic by pertinence to at least one class.
[009] In some embodiments, applying the at least one ML-based model may include applying at least one parametric ML-based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model may be respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
[010] In some embodiments, applying the nonparametric ML-based model may include calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class. [Oil] In some embodiments, applying the nonparametric ML-based model may further include classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
[012] In some embodiments, applying the parametric ML-based model may be performed when at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
[013] In some embodiments, the method may further include, when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sampling the current network traffic, to extract a second sample thereof; calculating a second vector, representing a vector embedding of the second sample in the feature space; concatenating the first vector with the second vector; applying the at least one of ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
[014] In some embodiments, the samples of previously classified network traffic may be selected from a set of samples of previously classified network traffic, and the method may further include, when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receiving a label, representing pertinence of the at least one class to the current network traffic, and updating the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
[015] In some embodiments, the method may further include retraining the parametric ML-based model based on the updated set of samples.
[016] In some embodiments, the feature space may be defined by initial features; and the method may further include generating new features, based on the updated set of samples; and enhancing the feature space by combining the new features with the initial features.
[017] In some embodiments, applying the parametric ML-based model may further include calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
[018] In some embodiments, applying the nonparametric ML-based model may be performed when the calculated confidence metric value does not exceed a predefined confidence metric value threshold. [019] In some embodiments, the nonparametric ML-based model may be a classification-by-retrieval (CbR) ML-based model.
[020] In some embodiments, the at least one class may represent a classification of the current network traffic by at least one of: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic;
(c) a quality-of-experience (QoE) characteristic of an application communicating via the current network traffic; (c) an active mode of an application communicating via the current network traffic.
[021] In some embodiments, the at least one class may represent a classification of the current network traffic by a type of an application communicating via the current network traffic; the method may further include extracting at least one packet flow within the first sample, associated with a specific application, and calculating the first vector may be performed based on the at least one packet flow.
[022] In some embodiments, the at least one packet flow may represent a plurality of packet flows, the method further include aggregating the plurality of packet flows, and calculating the first vector may be performed based on the aggregated plurality of packet flows.
[023] In some embodiments, extracting the first sample of the network traffic may be performed by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and
(d) detected activity of at least one of nodes communicating via the current network traffic after inactivity.
[024] In some embodiments, said at least one processor may be further configured to apply the at least one ML-based model further by applying at least one parametric ML-based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model may be respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
[025] In some embodiments, said at least one processor may be further configured to apply the nonparametric ML-based model by calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class.
[026] In some embodiments, said at least one processor may be further configured to apply the nonparametric ML-based model further by classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
[027] In some embodiments, said at least one processor may be further configured to apply the parametric ML-based model, provided that at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
[028] In some embodiments, said at least one processor may be further configured to: when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sample the current network traffic, to extract a second sample thereof; calculate a second vector, representing a vector embedding of the second sample in the feature space; concatenate the first vector with the second vector; and apply the at least one ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
[029] In some embodiments, said at least one processor may be further configured to: select the samples of previously classified network traffic from a set of samples of previously classified network traffic; when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receive a label, representing pertinence of the at least one class to the current network traffic; and update the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
[030] In some embodiments, said at least one processor may be further configured to retrain the parametric ML-based model based on the updated set of samples.
[031] In some embodiments, the feature space may be defined by initial features; and wherein said at least one processor may be further configured to: generate new features, based on the updated set of samples; and enhance the feature space by combining the new features with the initial features.
[032] In some embodiments, said at least one processor may be further configured to apply the parametric ML-based model further by calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
[033] In some embodiments, said at least one processor may be further configured to apply the nonparametric ML-based model, provided that the calculated confidence metric value does not exceed a predefined confidence metric value threshold.
[034] In some embodiments, the at least one class may represent a classification of the current network traffic by a type of an application communicating via the current network traffic; and said at least one processor may be further configured to: extract at least one packet flow within the first sample, associated with a specific application; and calculate the first vector based on the at least one packet flow.
[035] In some embodiments, the at least one packet flow may represent a plurality of packet flows; and said at least one processor may be further configured to aggregate the plurality of packet flows; and calculate the first vector based on the aggregated plurality of packet flows.
[036] In some embodiments, said at least one processor may be further configured to extract the first sample of the network traffic by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and (d) detected activity of at least one of nodes communicating via the current network traffic after inactivity.
BRIEF DESCRIPTION OF THE DRAWINGS
[037] The subject matter regarded as the invention is particularly pointed out and distinctly claimed in the concluding portion of the specification. The invention, however, both as to organization and method of operation, together with objects, features, and advantages thereof, may best be understood by reference to the following detailed description when read with the accompanying drawings in which:
[038] Fig. 1 is a block diagram, depicting a computing device which may be included in a system for classifying network traffic, according to some embodiments;
[039] Figs. 2A is a block diagram, depicting a system for classifying network traffic, according to some embodiments; [040] Figs. 2B is a block diagram, depicting a processing module of a system for classifying network traffic, according to some embodiments;
[041] Fig. 3 is a flow diagram, depicting a method of classifying network traffic, according to some embodiments.
[042] It will be appreciated that for simplicity and clarity of illustration, elements shown in the figures have not necessarily been drawn to scale. For example, the dimensions of some of the elements may be exaggerated relative to other elements for clarity. Further, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements.
DETAILED DESCRIPTION OF THE PRESENT INVENTION
[043] One skilled in the art will realize the invention may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. The foregoing embodiments are therefore to be considered in all respects illustrative rather than limiting of the invention described herein. Scope of the invention is thus indicated by the appended claims, rather than by the foregoing description, and all changes that come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein.
[044] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the present invention may be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail so as not to obscure the present invention. Some features or elements described with respect to one embodiment may be combined with features or elements described with respect to other embodiments. For the sake of clarity, discussion of same or similar features or elements may not be repeated.
[045] Although embodiments of the invention are not limited in this regard, discussions utilizing terms such as, for example, “processing,” “computing,” “calculating,” “determining,” “establishing”, “analyzing”, “checking”, “choosing”, “selecting”, “omitting”, “training” or the like, may refer to operation(s) and/or process(es) of a computer, a computing platform, a computing system, or other electronic computing device, that manipulates and/or transforms data represented as physical (e.g., electronic) quantities within the computer’s registers and/or memories into other data similarly represented as physical quantities within the computer’s registers and/or memories or other information non-transitory storage medium that may store instructions to perform operations and/or processes.
[046] Although embodiments of the invention are not limited in this regard, the terms “plurality” and “a plurality” as used herein may include, for example, “multiple” or “two or more”. The terms “plurality” or “a plurality” may be used throughout the specification to describe two or more components, devices, elements, units, parameters, or the like. The term “set” when used herein may include one or more items.
[047] Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Additionally, some of the described method embodiments or elements thereof can occur or be performed simultaneously, at the same point in time, concurrently, or iteratively and repeatedly.
[048] In embodiments of the present invention, some steps of the claimed method may be performed using machine-learning (ML)-based models. ML-based models may be configured or “trained” for a specific task, e.g., classification.
[049] In some embodiments, ML-based models may be or may include parametric ML- based models and/or nonparametric ML-based models.
[050] In the context of the present invention, the term “parametric ML-based model” may refer to an ML-based model that is trained to make an assumption according to a specific task using predefined form of a mapping function (mapping input and output values) and a fixed set of parameters thereof. That is, the mapping function and the set of parameters remain the same regardless of the number of training examples used for training. Training a parametric ML-based model for the specific task may involve adjusting the values of these parameters based on examples.
[051] Examples of parametric ML-based models may include Logistic Regression, Linear Discriminant Analysis, Perceptron, Naive Bayes, Artificial Neural Networks etc.
[052] In the context of the present invention, the term “nonparametric ML-based model” may refer to an ML-based model that does not have a predetermined form of the mapping function.
[053] Examples of nonparametric ML-based models may include k-Nearest Neighbours (and any other approximate-nearest-neighbor-based algorithm), Decision Trees (e.g., CART and C4.5), Support Vector Machines etc. [054] In some embodiments, parametric ML-based models may be artificial neural networks (ANN).
[055] A neural network (NN) or an artificial neural network (ANN), e.g., a neural network implementing a machine learning (ML) or artificial intelligence (Al) function, may refer to an information processing paradigm that may include nodes, referred to as neurons, organized into layers, with links between the neurons. The links may transfer signals between neurons and may be associated with weights. A NN may be configured or trained for a specific task, e.g., pattern recognition or classification. Training a NN for the specific task may involve adjusting these weights based on examples. Each neuron of an intermediate or last layer may receive an input signal, e.g., a weighted sum of output signals from other neurons, and may process the input signal using a linear or nonlinear function (e.g., an activation function). The results of the input and intermediate layers may be transferred to other neurons and the results of the output layer may be provided as the output of the NN. Typically, the neurons and links within a NN are represented by mathematical constructs, such as activation functions and matrices of data elements and weights. A processor, e.g., CPUs or graphics processing units (GPUs), or a dedicated hardware device may perform the relevant calculations.
[056] It should be obvious for the one ordinarily skilled in the art that various ML-based models can be implemented without departing from the essence of the present invention. It should also be understood, that in some embodiments ML-based model may be a single ML- based model or a set (ensemble) of ML-based models realizing as a whole the same function as a single one. Hence, in view of the scope of the present invention, the abovementioned variants should be considered equivalent.
[057] As can be seen, embodiments of the present invention may refer to extracting and analyzing samples of the network traffic. It should be understood that “sample” of the network traffic may represent a sequence of network packets, wherein the sequence may be of various sizes (include various number of packets) and may be taken from different parts of the network traffic within the network communication session. Hence, regardless of whether the content of the network packets is encrypted or not, there may be found distinguishing patterns characterizing the sequence of the network packets and not the separate packets, which may help revealing various attributes of traffic “behavior”. Hence, by relying on the features of sequences of network packets, a high efficiency of applying ML-based methods may be achieved, providing sufficient reliability of network traffic classification.
[058] Furthermore, as known, in order to be effective, currently applied approaches of network traffic classification require the analysis of the entire network traffic, that is analyze each packet of the traffic separately (e.g., by using DPI tools), from start to the end of the network communication session. Consequently, such approaches involve substantial computational loads. In contrast, the present invention does not rely on features of each separate packet, but rather on features of the sequence of packets, hence, it is enough to analyze only a sample of the traffic and not the full set of packets of the network communication session to make a reliable classification of the entire traffic. Hence, the present invention may provide additional improvement of the technological field of computer networking by reducing computational loads required to provide reliable network traffic classification and increasing the classification system throughput accordingly.
[059] As known, rapid increase of the number of applications and services communicating via the network makes the traffic constantly transforming, which also decreases efficiency of traffic monitoring and classification. For classification, most known solutions apply parametric ML-based models, that are pretrained by using supervised or semi- supervised ML algorithms. In order to provide reliable results, such pretraining requires applying large training datasets to cover the entire traffic variety and have sufficient number of examples of each of target classes. Obviously, it is extremely challenging to adapt these ML-based models for classifying constantly transforming network traffic and to keep them up to date, since their training and evaluation takes time. Moreover, when a parametric ML-based model tries to classify an input of an unknown class (i.e., the class, which was not represented in the training dataset), it intends to fit this input into the known set of classes, which leads to false positive classification results.
[060] As indicated above, some embodiments of the present invention may use a combination of parametric and nonparametric ML-based models. One of the known benefits of using nonparametric ML-based models lies in that they are much more flexible and adaptable to transformations in the input data. E.g., one of the common examples of nonparametric ML-based models - nearest neighbor algorithm and other approaches based thereon, like classification-by-retrieval (CbR) - do not require training or retraining at all. These approaches are based on comparing the input with each entry of the training dataset, calculating similarity metric values, and making classification based on the similarity metric values. If needed, the new class or the new representatives of the known class may be added just by supplementing the training dataset with the training examples of the respective class, without any actual retraining of the model.
[061] Hence, the usage of parametric and nonparametric ML-based models in combination, as it may be suggested herein, creates a scalable and adaptable approach of network traffic classification, thereby contributing into the abovementioned improvement of the technological field of computer networking by increasing the reliability of network traffic classification.
[062] Reference is now made to Fig. 1, which is a block diagram depicting a computing device, which may be included within an embodiment of the system for predicting cancer metastases location, according to some embodiments.
[063] Computing device 1 may include a processor or controller 2 that may be, for example, a central processing unit (CPU) processor, a chip or any suitable computing or computational device, an operating system 3, a memory device 4, instruction code 5, a storage system 6, input devices 7 and output devices 8. Processor 2 (or one or more controllers or processors, possibly across multiple units or devices) may be configured to carry out methods described herein, and/or to execute or act as the various modules, units, etc. More than one computing device 1 may be included in, and one or more computing devices 1 may act as the components of, a system according to embodiments of the invention.
[064] Operating system 3 may be or may include any code segment (e.g., one similar to instruction code 5 described herein) designed and/or configured to perform tasks involving coordination, scheduling, arbitration, supervising, controlling or otherwise managing operation of computing device 1, for example, scheduling execution of software programs or tasks or enabling software programs or other modules or units to communicate. Operating system 3 may be a commercial operating system. It will be noted that an operating system 3 may be an optional component, e.g., in some embodiments, a system may include a computing device that does not require or include an operating system 3.
[065] Memory device 4 may be or may include, for example, a Random-Access Memory (RAM), a read only memory (ROM), a Dynamic RAM (DRAM), a Synchronous DRAM (SD-RAM), a double data rate (DDR) memory chip, a Flash memory, a volatile memory, a non-volatile memory, a cache memory, a buffer, a short-term memory unit, a long-term memory unit, or other suitable memory units or storage units. Memory device 4 may be or may include a plurality of possibly different memory units. Memory device 4 may be a computer or processor non-transitory readable medium, or a computer non-transitory storage medium, e.g., a RAM. In one embodiment, a non-transitory storage medium such as memory device 4, a hard disk drive, another storage device, etc. may store instructions or code which when executed by a processor may cause the processor to carry out methods as described herein.
[066] Instruction code 5 may be any executable code, e.g., an application, a program, a process, task, or script. Instruction code 5 may be executed by processor or controller 2 possibly under control of operating system 3. For example, instruction code 5 may be a standalone application or an API module that may be configured to calculate prediction of a class to which the traffic pertains, as further described herein. Although, for the sake of clarity, a single item of instruction code 5 is shown in Fig. 1, a system according to some embodiments of the invention may include a plurality of executable code segments or modules similar to instruction code 5 that may be loaded into memory device 4 and cause processor 2 to carry out methods described herein.
[067] Storage system 6 may be or may include, for example, a flash memory as known in the art, a memory that is internal to, or embedded in, a micro controller or chip as known in the art, a hard disk drive, a CD-Recordable (CD-R) drive, a Blu-ray disk (BD), a universal serial bus (USB) device or other suitable removable and/or fixed storage unit. Various types of input and output data may be stored in storage system 6 and may be loaded from storage system 6 into memory device 4 where it may be processed by processor or controller 2. In some embodiments, some of the components shown in Fig. 1 may be omitted. For example, memory device 4 may be a non-volatile memory having the storage capacity of storage system 6. Accordingly, although shown as a separate component, storage system 6 may be embedded or included in memory device 4.
[068] Input devices 7 may be or may include any suitable input devices, components, or systems, e.g., a detachable keyboard or keypad, a mouse and the like. Output devices 8 may include one or more (possibly detachable) displays or monitors, speakers and/or any other suitable output devices. Any applicable input/output (RO) devices may be connected to Computing device 1 as shown by blocks 7 and 8. For example, a wired or wireless network interface card (NIC), a universal serial bus (USB) device or external hard drive may be included in input devices 7 and/or output devices 8. It will be recognized that any suitable number of input devices 7 and output device 8 may be operatively connected to Computing device 1 as shown by blocks 7 and 8.
[069] A system according to some embodiments of the invention may include components such as, but not limited to, a plurality of central processing units (CPU) or any other suitable multi-purpose or specific processors or controllers (e.g., similar to element 2), a plurality of input units, a plurality of output units, a plurality of memory units, and a plurality of storage units.
[070] Reference is now made to Figs. 2A and 2B, which depict system 10 for classifying network traffic and processing module 20 of system 10 for classifying network traffic respectively, according to some embodiments.
[071] According to some embodiments of the invention, system 10 may be implemented as a software module, a hardware module, or any combination thereof. For example, system 10 may be or may include a computing device such as element 1 of Fig. 1. Furthermore, system 10 may be adapted to execute one or more modules of instruction code (e.g., element 5 of Fig. 1) to request, receive, analyze, calculate and produce various data.
[072] As further described in detail herein, system 10 may be adapted to execute one or more modules of instruction code (e.g., element 5 of Fig. 1) in order to perform steps of the claimed method etc.
[073] As shown in Figs. 2A and 2B, arrows may represent flow of one or more data elements to and from system 10 and/or among modules or elements of system 10. Some arrows have been omitted in Figs. 2 A and 2B for the purpose of clarity.
[074] In some embodiments, system 10 may include preprocessing module 20.
[075] As shown in Fig. 2B, in some embodiments, preprocessing module 20 may include traffic capturing module 21. Traffic capturing module 21 may be configured to capture current network traffic 10A.
[076] It should be understood that, in the context of the present invention, when referring to the network traffic (e.g., network traffic 10A), the terms “capturing” and “receiving” shall be considered equivalent. It should also be understood that capturing may be performed either by the node (e.g., computing device 1 shown in Fig. 1) directly participating in the communication via the network traffic (e.g., server or client), or by the node intercepting communication of other nodes.
[077] In some embodiments, preprocessing module 20 may further include traffic sampling module 22. Traffic sampling module 22 may be configured to receive captured traffic 10A from traffic capturing module 21. Traffic sampling module 22 may be further configured to sample current network traffic 10A, in order to extract samples 22A thereof, e.g., including first sample 22A’.
[078] Traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a random distribution of the start point and the end point. In other words, traffic sampling module 22 may randomly select which portion of network traffic 10A to extract.
[079] Alternatively, traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic (e.g., network traffic 10A). In other words, traffic sampling module 22 may be configured to detect when specific node participating in the communication started and ended transmitting or receiving network traffic 10A and extract the respective portion of network traffic 10A.
[080] Alternatively, traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on a fixed period defined by the start point and the end point. That is, traffic sampling module 22 may be configured to extract samples of a fixed predefined size.
[081] Alternatively, traffic sampling module 22 may be configured to sample traffic 10A and extract samples 22 A thereof by setting a start point and an end point of each sample of samples 22A (e.g., first sample 22A’) based on detected activity of at least one of nodes communicating via the current network traffic (e.g., network traffic 10A) after inactivity. In other words, traffic sampling module 22 may be configured to detect when specific node participating in the communication switches between active/inactive states and trigger sample extraction accordingly. [082] In some embodiments, preprocessing module 20 may further include packet flow extraction module 23. Packet flow extraction module 23 may be configured to receive traffic samples 22A (e.g., first sample 22A’).
[083] Packet flow extraction module 23 may be further configured to extract packet flows 23A within samples 22A (e.g., first sample 22A’), associated with a specific application communicating via the current network traffic (e.g., video service, messenger, internet browser, gaming application etc.).
[084] In some embodiments, preprocessing module 20 may further include packet flow aggregation module 24. Packet flow aggregation module 24 may be configured to receive packet flows 23 A from packet flow extraction module 23. Packet flow aggregation module 24 may be further configured to aggregate the plurality of packet flows 23A and to output aggregated packet flows 24A. It should be understood that, within the scope of the present invention, various logic may be applied in order to perform packet flow aggregation. E.g., the plurality of packet flows (e.g., packet flows 23A) may be aggregated based on specific start and/or end time points of each flow or based on any other heuristics, e.g., detection of specific packet flows (e.g., detection of user request etc.).
[085] In some embodiments, preprocessing module 20 may further include embedding module 25. Embedding module 25 may be configured to receive aggregated packet flows 24A (or alternatively each packet flow 23A separately, or entire traffic sample 22A, e.g., first sample 22A’).
[086] Embedding module 25 may be further configured to calculate vectors 20A (e.g., first vector 20A’ of first sample 22 A’), each representing a vector embedding of the respective traffic sample 22A (e.g., first sample 22A’) in feature space 25’. Accordingly, in some embodiments, embedding module 25 may be configured to perform calculation of vectors 20A (e.g., first vector 20A’) based on packet flow (e.g., packet flow 23A) or based on aggregated plurality of packet flows (e.g., aggregated packet flows 24A). For example, vector 20A’ may represent a vector embedding of a single packet flow (e.g., packet flow 23A) or aggregated plurality of packet flows (e.g., aggregated packet flows 24A) within first sample 22A’ .
[087] It should be understood that the present invention is not limited to any specific features of the feature space used for embedding (e.g., feature space 25’). However, it may be implied herein that the features of the feature space (e.g., feature space 25’) characterize samples of the network traffic (e.g., samples 22A of traffic 10A) as representing the plurality of network packets, rather than each packet individually.
[088] E.g., such features may represent or be derived from such network traffic data as source ports (or combination of source ports present in the sequence of packets), destination ports (or combination of destination ports present in the sequence of packets), source IP addresses (or combination of source IP addresses present in the sequence of packets), destination IP addresses (or combination of destination IP addresses present in the sequence of packets), protocols (TCP/ UDP) etc.
[089] In some embodiments, the set of features of the feature space (e.g., feature space 25’) may be formed by applying deep learning clustering techniques on samples of the network traffic (e.g., samples 22A of traffic 10A).
[090] In some embodiments, the set of features of the feature space (e.g., features space 25’) may include the features listed in the table below.
[091] Table. Example of feature space 25’
[092] In some embodiments, preprocessing module 20 may be configured to output calculated vectors 20A (e.g., vector 20A’ of first sample 22A’).
[093] As shown in Fig. 2A, in some embodiments, system 10 may include control module 30, parametric ML-based model 40 and nonparametric ML-based model 50.
[094] In some embodiments, control module 30 may be configured to apply ML-based models (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the calculated vectors 20A (e.g., vector 20A’) to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., assigned class 40A).
[095] Parametric ML-based model 40 and nonparametric ML-based model 50 may be configured to classify the current network traffic (e.g., traffic 10A) by pertinence to classes representing: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic; (c) a quality -of-experience (QoE) characteristic of an application communicating via the current network traffic; (d) an active mode of an application communicating via the current network traffic (e.g., video call, audio call, messaging, file transferring etc.).
[096] It should be understood that the present invention is not limited to any particular purposes of network traffic classification. Hence, any reference to particular purpose of classification shall be considered a nonexclusive example.
[097] In some embodiments, parametric ML-based model 40 may be respectively pretrained to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., class 40A), based on the vector (e.g., vector 20A) representing a vector embedding of the traffic sample in a feature space (e.g., samples 22 A of traffic 10A in feature space 25’). E.g., parametric ML-based model 40 may be pretrained using commonly known supervised ML techniques, based on a training dataset including a plurality of training samples - vectors representing vector embeddings of a plurality of traffic samples in the feature space, said vectors correspondingly associated with a plurality of predefined classes. [098] In some embodiments, nonparametric ML-based model 50 may be configured to classify the current network traffic (e.g., traffic 10A) by pertinence to at least one class (e.g., class 40A) based on one or more respectively labeled vectors of samples of previously classified network traffic (e.g., vectors 70A of classified samples).
[099] In some embodiments, nonparametric ML-based model 50 may be a classification-by-retrieval (CbR) ML-based model or a nearest neighbor classifier.
[0100] In some embodiments, labeled vectors 70A of classified samples may represent a vector embedding of the respective classified samples in the same feature space (e.g., feature space 25’). In some embodiments, vectors 70A may be prestored and/or received from a separate database 70 of previously classified network traffic. In alternative embodiments, database 70 may store a set 70A’ of samples of previously classified network traffic (also referred herein as “labeled samples”), from which the samples of previously classified network traffic are selected. In such embodiments, embedding module 25 may be further configured to receive labeled samples and to calculate vectors 70A, each representing a vector embedding of the respective classified traffic sample in feature space 25’. It should be understood that the term “labeled” may refer herein to “labeled with indication of pertinence to the respective class (e.g., class 40A)”.
[0101] In some embodiments, parametric ML-based model 40 may be respectively pretrained using a training dataset formed based on the same labeled samples of classified network traffic (e.g., using labeled vectors 70A of classified samples), as further used by nonparametric ML-based model 50 to perform classification. In alternative embodiments, parametric ML-based model 40 may be pretrained using a training dataset formed based on labeled samples of classified network traffic, which are completely irrelevant to the labeled samples used by nonparametric ML-based model 50 to perform classification.
[0102] In some embodiments, nonparametric ML-based model 50 may be further configured to calculate similarity metric values 50A’ representing a degree of similarity between (i) the vectors 20A of samples of the current traffic (e.g., first vector 20A’) and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the respective classes (e.g., labeled vectors 70A). [0103] In some embodiments, nonparametric ML-based model 50 may be further configured to classify the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A), based on the one or more similarity metric values (e.g., similarity metric values 50A’), provided that the one or more similarity metric values (e.g., similarity metric values 50A’) exceed predefined similarity metric value threshold (e.g., similarity metric value threshold 50’). E.g., upon receiving vector 20A representing sample of the non-classified network traffic (e.g., first vector 20A’ of first sample 22A’ of traffic 10A), nonparametric ML-based model 50 may be further configured to evaluate similarity between the received vector (e.g., first vector 20A’) and one or more labeled vectors (e.g., labeled vectors 70A) by calculating respective similarity metric values 50A’.When at least one similarity metric value 50A’ exceeds predefined similarity metric value threshold 50’, it may indicate that vector 20A is sufficiently similar to respective labeled vector 70A. Hence, nonparametric ML-based model 50 may be configured to classify the received vector 20A (e.g., first vector 20A’ and, therefore, traffic 10A) by pertinence to the same class as the label of the respective labeled vector (e.g., vector 70A) represents.
[0104] In some embodiments, parametric ML-based model 40 may be further configured to calculate confidence metric value 40A’ representing a confidence of classifying the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A).
[0105] It should be understood that the scope of the present invention intends to cover various logic of utilizing parametric and nonparametric classification in combination. Consequently, it should be understood that the present invention is not limited to any specific embodiment in this regard.
[0106] Thus, in some embodiments, control module 30 may be configured to apply nonparametric ML-based model 50 when calculated confidence metric value 40 A’ does not exceed predefined confidence metric value threshold 40’ (that is, when parametric ML- based model 50 is not confident enough in assigning any of target classes (e.g., class 40A)). [0107] In the present invention, the problem of adjustment of the network traffic classification system to the constantly evolving network traffic, in some embodiments, is addressed based on the following approach of dealing with OOD (out-of-distribution) network traffic data. [0108] Dramatic drop of classification reliability with respect to samples pertaining to OOD data is a known drawback of parametric ML-based models (e.g., parametric ML-based model 40). In this context, OOD data may refer to data which, in the respective feature space (e.g., feature space 25’), is located sufficiently far from the distribution of training data (e.g., training dataset formed based on set 70A’ of samples of previously classified network traffic), that was used for pretraining parametric ML-based model (e.g., parametric ML- based model 40). Hence, detecting and filtering out samples pertaining to OOD data is considered a highly important aspect of parametric ML-based classification.
[0109] Hence, in some embodiments, nonparametric ML-based model 50 may be configured to evaluate whether vector 20A of sample 22A of current network traffic 10A pertains to OOD data. In particular, in some alternative embodiments, control module 30 may be configured to apply parametric ML-based model 40 only when at least one of one or more similarity metric values 50A’ exceed predefined similarity metric value threshold 50’, which may indicate that the respective vector 20A (e.g., first vector 20A’) does not pertain to OOD data.
[0110] Furthermore, in some embodiments, when none of the one or more similarity metric values (e.g., similarity metric values 50A’) exceed the predefined similarity metric value threshold (e.g., similarity metric value threshold 50’), which may indicate that the respective vector 20A (e.g., first vector 20A’) pertains to OOD data, nonparametric ML- based model 50 may be configured to output OOD indication 10A”.
[0111] In some embodiments, traffic sampling module 22 may be further configured to receive OOD indication 10 A’ ’ . Traffic sampling module 22 may be further configured, upon receiving OOD indication 10A”, sample the current network traffic (e.g., traffic 10A), to extract a second sample thereof (e.g., second sample 22A”). Traffic sampling module 22 may be further configured to transfer the second sample (e.g., second sample 22A”) to embedding module 25.
[0112] Embedding module 25 may be further configured to calculate a second vector 20A”, representing a vector embedding of the second sample 22 A” in the feature space (e.g., feature space 25’).
[0113] In some alternative embodiments, preprocessing module 20 may be further configured to apply packet flow extraction module 23 and packet flow aggregation module 24 with respect to the second sample (e.g., second sample 22A”), same as it was described with reference to the first sample (e.g., first sample 22A’). Accordingly, in respective embodiments, embedding module 25 may be configured to perform calculation of second vector 20A’ ’ , based on respective packet flow or based on respective aggregated plurality of packet flows.
[0114] In some embodiments, preprocessing module 20 may further include vector concatenation module 26. Vector concatenation module 26 may be configured to receive plurality of vectors 20A calculated by embedding module 25 (e.g., first vector 20A’ and second vector 20 A”). Vector concatenation module may be further configured to concatenate plurality of vectors 20A (e.g., first vector 20A’ and second vector 20A”) and output concatenated vectors 20 A’ ’ ’ .
[0115] In some embodiments, control module 30 may be further configured to apply the at least one of ML-based model (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the concatenated vectors (e.g., concatenated vectors 20 A’”) to classify the current network traffic (e.g., traffic 10A) by pertinence to the at least one class (e.g., class 40A).
[0116] In some embodiments, the sequence of actions including extracting new sample (e.g., second sample 22A”) of the current network traffic (e.g., traffic 10A), calculating vector of the new sample (e.g., second vector 20A”), concatenating new vector with the previously calculated ones (e.g., second vector 20A” with first vector 20A’), and applying the ML-based models (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) thereon, may be performed iteratively. In some embodiments, this iterative sequence of actions may be performed until the sufficient level of similarity metric value is achieved (e.g., until one or more similarity metric values 50 A’ exceed predefined similarity metric value threshold 50’).
[0117] In some embodiments, system 10 may further include review system 60. In some embodiments, when none of the one or more similarity metric values (e.g., similarity metric values 50A’) exceeds the predefined similarity metric value threshold (e.g., similarity metric value threshold 50’), system 10 may be configured to transmit respective sample or plurality of samples (e.g., samples 22A’ and 22A”) to review system 60. In some embodiments, the involvement of review system 60 may be triggered by receiving OOD indication 10A”. Review system 60 may be configured to receive a label (e.g., label 60A), representing pertinence of the at least one class (e.g., class 40A) to the current network traffic (e.g., traffic 10A).
[0118] In some embodiments, review system 60 may be configured to apply various techniques of detailed analysis of the network traffic (e.g., traffic 10A). E.g., review system 60 may apply DPI methods in combination with decryption techniques, to reveal the content of respective packets. In some embodiments, review system 60 may be configured to request and receive label 60A from a third-party deep packet analysis service.
[0119] In some alternative embodiments, review system 60 may be configured to provide respective samples (e.g., samples 22A’ and 22A”) to user interface (UI) module (not shown in figures) for further manual or semi-automatic review, and to receive label 60A via UI module from the user.
[0120] Hence, in some embodiments, system 10 may be configured to output the result of classification (e.g., classified current network traffic 10A’). The result of classification may represent current network traffic (e.g., traffic 10A) and assigned class (e.g., class 40A) thereto.
[0121] Depending on the embodiments of the present invention, there may be various logic applied with respect to the way the final decision on which class to assign is made. E.g., in some nonexclusive embodiments, system 10 is configured to output the result of classification (e.g., classified current network traffic 10 A’) when both similarity metric value (e.g., similarity metric value 50A’) and confidence metric value (e.g., confidence metric value 40A’) exceed the similarity metric value threshold (e.g., similarity metric value threshold 50’) and confidence metric value threshold (e.g., confidence metric value threshold 40’) accordingly. It should be understood that other embodiments in this regard may be covered by the scope of the present invention.
[0122] Once the classification of the current network traffic (e.g., traffic 10A) is made (either by applying ML-based models 40 and 50 or by receiving label via review system 60) in some embodiments, system 10 may be configured to update the set 70A’ of samples by adding the samples of the current network traffic (e.g., first sample 22 A’ and/or second sample 22A” of traffic 10A) classified based on the label (e.g., label 60 A) or in result of classification by parametric and/or nonparametric ML-based models (e.g., parametric ML- based model 40 and nonparametric ML-based model 50) thereto, thereby producing updated set 70A” of samples of previously classified network traffic 10A. [0123] In order to further increase reliability of network traffic classification, thereby contributing to the abovementioned technical improvement, in some embodiments, system 10 may be further configured to retrain the parametric ML-based model (e.g., parametric ML-based model 40) based on the updated set of samples (e.g., updated set 70A”). It should be understood that, since nonparametric ML-based models (e.g., nonparametric ML-based model 50) do not require training, no additional actions are required in order to improve performance of nonparametric ML-based model, except for updating the set of samples of previously classified network traffic (e.g., set 70A’). Thereby, system 10 may constantly adapt to new unknown types of network traffic (e.g., traffic 10A) and provide sufficient reliability of network traffic classification.
[0124] However, as indicated above, network traffic constantly evolves - new applications communicating via network traffic and new types of information transmitted via the network arise. Consequently, at some point, traffic may change substantially and it may no longer be enough to update the set of samples of previously classified network traffic (e.g., set 70A’) and to retrain parametric ML-based model (e.g., parametric ML-based model 40) in order to achieve desired classification reliability. Such network traffic may have new features that were not present in previously classified traffic.
[0125] In order to address the abovementioned issue and thereby increase reliability of network traffic classification, the following is suggested. In some embodiments, feature space 25’ may be defined by initial features. In some embodiments, embedding module 25 may be further configured to generate new features, based on the updated set of samples (e.g., updated set 70A”), and enhance the feature space (e.g., feature space 25’) by combining the new features with the initial features. Hence, embedding module 25 may be further configured to calculate vectors representing vector embeddings of samples of new network traffic in the enhanced feature space 25”.
[0126] In some embodiments, in order to cover both “previous” traffic (e.g., traffic not having new features) and “new” traffic (e.g., having new features) sparse vectors may be used. In such embodiments, vectors of samples of “old” traffic may have zero values with respect to new features.
[0127] Hence, detecting samples 22A of network traffic 10A pertaining to OOD data and performing abovementioned actions thereafter (extracting new sample 22 A”, calculating vector 20 A” thereof, concatenating the calculated vector 20 A” with the previous vector 20A’, applying review system 60, updating set 70 A’ of samples, retraining parametric ML- based model 40, enhancing feature space 25’ etc.) contribute to the abovementioned improvement of the network traffic classification. Thereby, the system may be configured to continuously adapt to new unknown network traffic and reliability of network traffic classification may thus be increased.
[0128] Referring now to Fig. 3, a flow diagram is presented, depicting a method of classifying network traffic, by at least one processor, according to some embodiments.
[0129] As shown in step S1005, the at least one processor (e.g., processor 2 of Fig. 1) may perform capturing of a current network traffic (e.g., current network traffic 10A). Step S1005 may be carried out by traffic capturing module 21 (as described with reference to Fig. 2B).
[0130] As shown in step S1010, the at least one processor (e.g., processor 2 of Fig. 1) may perform sampling of the current network traffic (e.g., current network traffic 10A), to extract a first sample thereof (e.g., first sample 22A’). Step S1010 may be carried out by traffic sampling module 22 (as described with reference to Fig. 2B).
[0131] As shown in step S1015, the at least one processor (e.g., processor 2 of Fig. 1) may perform calculating of a first vector (e.g., first vector 20A’), representing a vector embedding of the first sample (e.g., first sample 22A’) in a feature space (e.g., feature space 25’). Step S 1015 may be carried out by embedding module 25 (as described with reference to Fig. 2B).
[0132] As shown in step S1020, the at least one processor (e.g., processor 2 of Fig. 1) may perform applying of at least one machine-learning (ML)-based model (e.g., parametric ML-based model 40 and/or nonparametric ML-based model 50) on the first vector (e.g., first vector 20A’) to classify the current network traffic (e.g., current network traffic 10A) by pertinence to at least one class (e.g., class 40A). Step S1020 may be carried out by control module 30, parametric ML-based model 40 and nonparametric ML-based model 50 (as described with reference to Fig. 2A).
[0133] As can be seen from the provided description, the claimed invention represents the system and method of classifying network traffic which provide an improvement of the technological field of computer networking by increasing reliability of network traffic classification. In particular, the claimed invention provides a reliable instrument for classifying encrypted network traffic. [0134] Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Furthermore, all formulas described herein are intended as examples only and other or different formulas may be used. Additionally, some of the described method embodiments or elements thereof may occur or be performed at the same point in time.
[0135] While certain features of the invention have been illustrated and described herein, many modifications, substitutions, changes, and equivalents may occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and changes as fall within the true spirit of the invention.
[0136] Various embodiments have been presented. Each of these embodiments may of course include features from other embodiments presented, and embodiments not specifically described may include various features described herein.

Claims

1. A method of classifying network traffic by at least one processor, the method comprising; capturing a current network traffic; sampling the current network traffic, to extract a first sample thereof; calculating a first vector, representing a vector embedding of the first sample in a feature space; applying at least one machine-learning (ML)-based model on the first vector to classify the current network traffic by pertinence to at least one class.
2. The method of claim 1, wherein applying the at least one ML -based model comprises applying at least one parametric ML -based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model is respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
3. The method of claim 2, wherein applying the nonparametric ML-based model comprises calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class.
4. The method of claim 3, wherein applying the nonparametric ML-based model further comprises classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
5. The method according to any one of claims 3 and 4, wherein applying the parametric ML-based model is performed when at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
6. The method according to any one of claims 3-5, wherein the method further comprises: when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sampling the current network traffic, to extract a second sample thereof; calculating a second vector, representing a vector embedding of the second sample in the feature space; concatenating the first vector with the second vector; and applying the at least one ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
7. The method according to any one of claims 3-6, wherein the samples of previously classified network traffic are selected from a set of samples of previously classified network traffic; and wherein the method further comprises, when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receiving a label, representing pertinence of the at least one class to the current network traffic; and updating the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
8. The method of claim 7, further comprising retraining the parametric ML-based model based on the updated set of samples.
9. The method according to any one of claims 7-8, wherein the feature space is defined by initial features; and the method further comprises generating new features, based on the updated set of samples; and enhancing the feature space by combining the new features with the initial features.
10. The method according to any one of claims 2-9, wherein applying the parametric ML-based model further comprises calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
11. The method of claim 10, wherein applying the nonparametric ML-based model is performed when the calculated confidence metric value does not exceed a predefined confidence metric value threshold.
12. The method according to any one of claims 2-11, wherein the nonparametric ML- based model is a classification-by-retrieval (CbR) ML-based model.
13. The method according to any one of claims 1-12, wherein the at least one class represents a classification of the current network traffic by at least one of: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic; (c) a quality-of-experience (QoE) characteristic of an application communicating via the current network traffic; (d) an active mode of an application communicating via the current network traffic.
14. The method according to any one of claims 1-13, wherein the at least one class represents a classification of the current network traffic by a type of an application communicating via the current network traffic; and wherein the method further comprises extracting at least one packet flow within the first sample, associated with a specific application; and wherein calculating the first vector is performed based on the at least one packet flow.
15. The method of claim 14, wherein the at least one packet flow represents a plurality of packet flows; and the method further comprises aggregating the plurality of packet flows; and wherein calculating the first vector is performed based on the aggregated plurality of packet flows.
16. The method according to any one of claims 1-15, wherein extracting the first sample of the network traffic is performed by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and (d) detected activity of at least one of nodes communicating via the current network traffic after inactivity.
17. A system for classifying a network traffic, the system comprising: a non-transitory memory device, wherein modules of instruction code are stored, and at least one processor associated with the memory device, and configured to execute the modules of instruction code, whereupon execution of said modules of instruction code, the at least one processor is configured to: capture a current network traffic; sample the current network traffic, to extract a first sample thereof; calculate a first vector, representing a vector embedding of the first sample in a feature space; apply at least one machine-learning (ML)-based model on the first vector to classify the current network traffic by pertinence to at least one class.
18. The system of claim 17, wherein said at least one processor is further configured to apply the at least one ML-based model further by applying at least one parametric ML- based model and at least one nonparametric ML-based model, wherein the at least one parametric ML-based model is respectively pretrained to classify the current network traffic by pertinence to at least one class, based on the first vector.
19. The system of claim 18, wherein said at least one processor is further configured to apply the nonparametric ML-based model by calculating one or more similarity metric values representing a degree of similarity between (i) the first vector and (ii) one or more vectors of samples of previously classified network traffic, labeled based on pertinence to the at least one class.
20. The system of claim 19, wherein said at least one processor is further configured to apply the nonparametric ML-based model further by classifying the current network traffic by pertinence to the at least one class, based on the one or more similarity metric values, provided that the one or more similarity metric values exceed a predefined similarity metric value threshold.
21. The system according to any one of claims 19 and 20, wherein said at least one processor is further configured to apply the parametric ML-based model, provided that at least one of the one or more similarity metric values exceeds a predefined similarity metric value threshold.
22. The system according to any one of claims 19-21, wherein said at least one processor is further configured to: when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, sample the current network traffic, to extract a second sample thereof; calculate a second vector, representing a vector embedding of the second sample in the feature space; concatenate the first vector with the second vector; and apply the at least one ML-based model on the concatenated vectors to classify the current network traffic by pertinence to the at least one class.
23. The system according to any one of claims 19-22, wherein said at least one processor is further configured to: select the samples of previously classified network traffic from a set of samples of previously classified network traffic; when none of the one or more similarity metric values exceeds a predefined similarity metric value threshold, receive a label, representing pertinence of the at least one class to the current network traffic; and update the set of samples by adding the first sample of the current network traffic classified based on the label thereto.
24. The system of claim 23, wherein said at least one processor is further configured to retrain the parametric ML-based model based on the updated set of samples.
25. The system according to any one of claims 23-24, wherein the feature space is defined by initial features; and wherein said at least one processor is further configured to: generate new features, based on the updated set of samples; and enhance the feature space by combining the new features with the initial features.
26. The system according to any one of claims 18-25, wherein said at least one processor is further configured to apply the parametric ML-based model further by calculating a confidence metric value representing a confidence of classifying the current network traffic by pertinence to the at least one class.
27. The system of claim 26, wherein said at least one processor is further configured to apply the nonparametric ML-based model, provided that the calculated confidence metric value does not exceed a predefined confidence metric value threshold.
28. The system according to any one of claims 18-27, wherein the nonparametric ML- based model is a classification-by-retrieval (CbR) ML-based model.
29. The system according to any one of claims 17-28, wherein the at least one class represents a classification of the current network traffic by at least one of: (a) a type of an application communicating via the current network traffic; (b) a presence of malware activity within the current network traffic; (c) a quality-of-experience (QoE) characteristic of an application communicating via the current network traffic; (d) an active mode of an application communicating via the current network traffic.
30. The system according to any one of claims 1-13, wherein the at least one class represents a classification of the current network traffic by a type of an application communicating via the current network traffic; and wherein said at least one processor is further configured to: extract at least one packet flow within the first sample, associated with a specific application; and calculate the first vector based on the at least one packet flow.
31. The system of claim 30, wherein the at least one packet flow represents a plurality of packet flows; and said at least one processor is further configured to aggregate the plurality of packet flows; and calculate the first vector based on the aggregated plurality of packet flows.
32. The system according to any one of claims 17-31, wherein said at least one processor is further configured to extract the first sample of the network traffic by setting a start point and an end point of the first sample based on at least one of the following: (a) a random distribution of the start point and the end point; (b) a start point and an end point of an active phase of at least one of nodes communicating via the current network traffic; (c) a fixed period defined by the start point and the end point; and (d) detected activity of at least one of nodes communicating via the current network traffic after inactivity.
EP24763365.4A 2023-02-27 2024-02-26 System and method of classifying network traffic Pending EP4674090A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US202363448460P 2023-02-27 2023-02-27
PCT/IL2024/050220 WO2024180543A1 (en) 2023-02-27 2024-02-26 System and method of classifying network traffic

Publications (1)

Publication Number Publication Date
EP4674090A1 true EP4674090A1 (en) 2026-01-07

Family

ID=92589329

Family Applications (1)

Application Number Title Priority Date Filing Date
EP24763365.4A Pending EP4674090A1 (en) 2023-02-27 2024-02-26 System and method of classifying network traffic

Country Status (2)

Country Link
EP (1) EP4674090A1 (en)
WO (1) WO2024180543A1 (en)

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10867036B2 (en) * 2017-10-12 2020-12-15 Cisco Technology, Inc. Multiple pairwise feature histograms for representing network traffic
US11429891B2 (en) * 2018-03-07 2022-08-30 At&T Intellectual Property I, L.P. Method to identify video applications from encrypted over-the-top (OTT) data
US20210303984A1 (en) * 2020-03-24 2021-09-30 Fortinet, Inc. Machine-learning based approach for classification of encrypted network traffic
US20220053010A1 (en) * 2020-08-13 2022-02-17 Tweenznet Ltd. System and method for determining a communication anomaly in at least one network
CN113037730B (en) * 2021-02-27 2023-06-20 中国人民解放军战略支援部队信息工程大学 Network encryption traffic classification method and system based on multi-feature learning

Also Published As

Publication number Publication date
WO2024180543A1 (en) 2024-09-06

Similar Documents

Publication Publication Date Title
US12206699B1 (en) Identifying high-influence features for model-detected anomalies
Dias et al. An innovative approach for real-time network traffic classification
KR102480204B1 (en) Continuous learning for intrusion detection
US20220224725A1 (en) Classification of unknown network traffic
US20220053010A1 (en) System and method for determining a communication anomaly in at least one network
US11716338B2 (en) System and method for determining a file-access pattern and detecting ransomware attacks in at least one computer network
US10972495B2 (en) Methods and apparatus for detecting and identifying malware by mapping feature data into a semantic space
US12363163B2 (en) NLP based identification of cyberattack classifications
US10218716B2 (en) Technologies for analyzing uniform resource locators
Bowen et al. BLoCNet: a hybrid, dataset-independent intrusion detection system using deep learning: B. Bowen et al.
US20190235944A1 (en) Anomaly Detection using Circumstance-Specific Detectors
US10284570B2 (en) System and method to detect threats to computer based devices and systems
CN111626431A (en) System and method for operating a data center based on a generative machine learning pipeline
Lin et al. Statistical twitter spam detection demystified: performance, stability and scalability
US12592973B2 (en) System and method for security control over data flows in distributed computing systems
Perera Jayasuriya Kuranage et al. Network traffic classification using machine learning for software defined networks
Roy et al. Fast and lean encrypted Internet traffic classification
US11829866B1 (en) System and method for hierarchical deep semi-supervised embeddings for dynamic targeted anomaly detection
US20180032917A1 (en) Hierarchical classifiers
US11288097B2 (en) Automated hardware resource optimization
JP2020160743A (en) Evaluation device, evaluation method, and evaluation program
Sivasubramanian et al. Feature extraction and anomaly detection using different autoencoders for modeling intrusion detection systems
Dhahir A hybrid approach for efficient DDoS detection in network traffic using CBLOF-based feature engineering and XGBoost
CN107967488A (en) The sorting technique and categorizing system of a kind of server
US20250141891A1 (en) Systems and methods for evaluating entities communicating over a network

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250926

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR