arXiv:2503.03747cs.CRcs.LG2025-03被引 12

用语言描述+网络包数据,让系统更懂加密流量的异常行为。

PacketCLIP: Multi-Modal Embedding of Network Traffic and Language for Cybersecurity Reasoning

  • 用对比学习融合网络包与文本语义,构建多模态嵌入
  • 在加密流量上达到95%平均AUC,比基线高11.6%
  • 模型体积缩小92%,适合实时检测场景

流量分类对网络安全至关重要,但加密流量带来巨大挑战。我们提出PacketCLIP,一种结合包数据与自然语言语义的多模态框架,通过对比预训练和分层图神经网络推理实现高效分类。该框架将语义推理与快速分类结合,可鲁棒检测加密网络流中的异常。通过对齐文本描述与包行为,提升了可解释性、可扩展性和实际应用能力。PacketCLIP在多个安全场景中实现95%平均AUC,优于基线11.6%,模型规模减少92%,适用于资源受限环境下的实时异常检测。该工作为加密流量分类与网络入侵检测提供了高效、可解释的可扩展解决方案。

原文摘要 · Abstract (English)

Traffic classification is vital for cybersecurity, yet encrypted traffic poses significant challenges. We present PacketCLIP, a multi-modal framework combining packet data with natural language semantics through contrastive pretraining and hierarchical Graph Neural Network (GNN) reasoning. PacketCLIP integrates semantic reasoning with efficient classification, enabling robust detection of anomalies in encrypted network flows. By aligning textual descriptions with packet behaviors, it offers enhanced interpretability, scalability, and practical applicability across diverse security scenarios. PacketCLIP achieves a 95% mean AUC, outperforms baselines by 11.6%, and reduces model size by 92%, making it ideal for real-time anomaly detection. By bridging advanced machine learning techniques and practical cybersecurity needs, PacketCLIP provides a foundation for scalable, efficient, and interpretable solutions to tackle encrypted traffic classification and network intrusion detection challenges in resource-constrained environments.

网络安全多模态图神经网络异常检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。