CRJul 8

Multi-view Correlation-aware Network Traffic Detection on Flow Hypergraph

arXiv:2501.086108.85 citationsh-index: 33
Predicted impact top 40% in CR · last 90 daysOriginality Incremental advance
AI Analysis

For network security practitioners, FlowID improves detection of malicious traffic by addressing limitations of single-perspective methods and poor generalization.

FlowID proposes a multi-view correlation-aware framework for network traffic detection that captures temporal and interaction features via a hypergraph encoder and uses dual-contrastive learning to handle data imbalance and label scarcity. It outperforms existing methods on five real-world datasets, achieving significant gains in accuracy, robustness, and generalization for malicious traffic detection.

As the Internet rapidly expands, the increasing complexity and diversity of network activities pose significant challenges to effective network governance and security regulation. Network traffic, which serves as a crucial data carrier of network activities, has become indispensable in this process. Network traffic detection aims to monitor, analyze, and evaluate the data flows transmitted across the network to ensure network security and optimize performance. However, existing network traffic detection methods generally suffer from several limitations: 1) a narrow focus on characterizing traffic features from a single perspective; 2) insufficient exploration of discriminative features for different traffic; 3) poor generalization to different traffic scenarios. To address these issues, we propose a multi-view correlation-aware framework named FlowID for network traffic detection. FlowID captures multi-view traffic features via temporal and interaction awareness, while a hypergraph encoder further explores higher-order relationships between flows. To overcome the challenges of data imbalance and label scarcity, we design a dual-contrastive proxy task, enhancing the framework's ability to differentiate between various traffic flows through flow-to-flow and group-to-group contrast. Extensive experiments on five real-world datasets demonstrate that FlowID significantly outperforms existing methods in accuracy, robustness, and generalization across diverse network scenarios, particularly in detecting malicious traffic.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes