arXiv:2410.03728cs.NIcs.AI2024-10被引 6

公开10万条加密QUIC流量数据,助力网络分析与安全研究

Exploring QUIC Dynamics: A Large-Scale Dataset for Encrypted Traffic Analysis

  • 构建10万条带标签的QUIC流量数据,支持多实现和可控解密
  • 用图像表示法实现97%准确率的HTTP/3响应预测
  • 适合做加密流量分析、协议安全和网络监控的研究者使用

QUIC传输协议的普及改变了加密网络流量格局,但现有数据集在规模、元数据和解密能力上难以支撑稳健的加密流量研究。我们提出VisQUIC,一个包含超过44,000个网站的10万条已标注QUIC流量记录的大规模数据集,采集周期为四个月。与以往数据集不同,VisQUIC提供SSL密钥以实现可控解密,支持Chromium QUIC、Facebook的mvfst、Cloudflare的quiche等多种实现,并引入新颖的图像表示方法,支持基于机器学习的加密流量分析。数据集还包含标准化的基准测试工具,确保可复现性。为展示其价值,我们设计了一个在加密QUIC流量中估计HTTP/3响应的基准任务,仅依赖可观测包特征即达到97%准确率。通过公开发布VisQUIC,我们为加密流量分析、QUIC安全研究和网络监控提供了开放基础。

原文摘要 · Abstract (English)

The increasing adoption of the QUIC transport protocol has transformed encrypted web traffic, necessitating new methodologies for network analysis. However, existing datasets lack the scope, metadata, and decryption capabilities required for robust benchmarking in encrypted traffic research. We introduce VisQUIC, a large-scale dataset of 100,000 labeled QUIC traces from over 44,000 websites, collected over four months. Unlike prior datasets, VisQUIC provides SSL keys for controlled decryption, supports multiple QUIC implementations (Chromium QUIC, Facebooks mvfst, Cloudflares quiche), and introduces a novel image-based representation that enables machine learning-driven encrypted traffic analysis. The dataset includes standardized benchmarking tools, ensuring reproducibility. To demonstrate VisQUICs utility, we present a benchmarking task for estimating HTTP/3 responses in encrypted QUIC traffic, achieving 97% accuracy using only observable packet features. By publicly releasing VisQUIC, we provide an open foundation for advancing encrypted traffic analysis, QUIC security research, and network monitoring.

QUIC加密流量数据集机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。