Pith. sign in

REVIEW 2 cited by

Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph Analysis

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2301.13686 v1 pith:LYAMMC3B submitted 2023-01-31 cs.CR

classification cs.CR
keywords graphhypervisiontrafficattacksencryptedmaliciouspatternsdetect
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

In this paper, we propose HyperVision, a realtime unsupervised machine learning (ML) based malicious traffic detection system. Particularly, HyperVision is able to detect unknown patterns of encrypted malicious traffic by utilizing a compact inmemory graph built upon the traffic patterns. The graph captures flow interaction patterns represented by the graph structural features, instead of the features of specific known attacks. We develop an unsupervised graph learning method to detect abnormal interaction patterns by analyzing the connectivity, sparsity, and statistical features of the graph, which allows HyperVision to detect various encrypted attack traffic without requiring any labeled datasets of known attacks. Moreover, we establish an information theory model to demonstrate that the information preserved by the graph approaches the ideal theoretical bound. We show the performance of HyperVision by real-world experiments with 92 datasets including 48 attacks with encrypted malicious traffic. The experimental results illustrate that HyperVision achieves at least 0.92 AUC and 0.86 F1, which significantly outperform the state-of-the-art methods. In particular, more than 50% attacks in our experiments can evade all these methods. Moreover, HyperVision achieves at least 80.6 Gb/s detection throughput with the average detection latency of 0.83s.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Magnifier: Detecting Network Access via Lightweight Traffic-based Fingerprints

    cs.NI 2024-12 conditional novelty 6.0 of 10

    Magnifier uses Domain Name Forest fingerprints of a phone's connection-burst domain names to detect its network access and identify its brand and model from gateway traffic.

  2. M3S-UPD: Efficient Multi-Stage Self-Supervised Learning for Fine-Grained Encrypted Traffic Classification with Unknown Pattern Discovery

    cs.CR 2025-05 conditional novelty 5.0 of 10

    M3S-UPD combines DBSCAN embedding clustering, class-centroid alignment, and probability consistency checks to self-train an encrypted-traffic classifier that detects unknown traffic from limited labels.

Pith tools