Hybrid multicriteria fuzzy classification of network traffic patterns, anomalies, and protocols

F. Al-Obeidat, E. S.M. El-Alfy*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

16 Scopus citations

Abstract

Traffic classification in computer networks has very significant roles in network operation, management, and security. Examples include controlling the flow of information, allocating resources effectively, provisioning quality of service, detecting intrusions, and blocking malicious and unauthorized access. This problem has attracted a growing attention over years and a number of techniques have been proposed ranging from traditional port-based and payload inspection of TCP/IP packets to supervised, unsupervised, and semi-supervised machine learning paradigms. With the increasing complexity of network environments and support for emerging mobility services and applications, more robust and accurate techniques need to be investigated. In this paper, we propose a new supervised hybrid machine-learning approach for ubiquitous traffic classification based on multicriteria fuzzy decision trees with attribute selection. Moreover, our approach can handle well the imbalanced datasets and zero-day applications (i.e., those without previously known traffic patterns). Evaluating the proposed methodology on several benchmark real-world traffic datasets of different nature demonstrated its capability to effectively discriminate a variety of traffic patterns, anomalies, and protocols for unencrypted and encrypted traffic flows. Comparing with other methods, the performance of the proposed methodology showed remarkably better classification accuracy.

Original languageEnglish
Pages (from-to)777-791
Number of pages15
JournalPersonal and Ubiquitous Computing
Volume23
Issue number5-6
DOIs
StatePublished - 1 Nov 2019

Bibliographical note

Publisher Copyright:
© 2017, Springer-Verlag London Ltd., part of Springer Nature.

Keywords

  • Decision trees
  • Encrypted traffic
  • Intrusion detection
  • Multicriterion fuzzy decision making
  • Network management and security
  • Network traffic classification

ASJC Scopus subject areas

  • Hardware and Architecture
  • Computer Science Applications
  • Management Science and Operations Research
  • Library and Information Sciences

Fingerprint

Dive into the research topics of 'Hybrid multicriteria fuzzy classification of network traffic patterns, anomalies, and protocols'. Together they form a unique fingerprint.

Cite this