计算机工程与应用 ›› 2025, Vol. 61 ›› Issue (21): 61-80.DOI: 10.3778/j.issn.1002-8331.2501-0218

• 热点与综述 • 上一篇    下一篇

基于深度学习的加密流量分类研究综述

王影,王钢,高雲鹏,霍闯   

  1. 内蒙古工业大学 数据科学与应用学院,呼和浩特 010080
  • 出版日期:2025-11-01 发布日期:2025-10-31

Survey of Research on Encrypted Traffic Classification Based on Deep Learning

WANG Ying, WANG Gang, GAO Yunpeng, HUO Chuang   

  1. School of Data Science and Application, Inner Mongolia University of Technology, Hohhot 010080, China
  • Online:2025-11-01 Published:2025-10-31

摘要: 随着互联网技术的迅速发展,网络流量类型变得复杂多变。同时为确保数据安全,大量信息通过加密协议进行传输,加密条件下流量原始信息不可见,这导致传统的流量分类方法不再适用。在此背景下,加密流量分类技术应运而生,它旨在识别和区分加密流量的类型和来源。加密流量分类不仅要正确区分各类已知流量做好流量管控,还要识别出可能携带恶意信息的未知流量做好安全防护。介绍了在通用环境下加密流量分类技术的研究现状,从已知流量分类、未知流量分类和数据集三个方面展开分析,探讨了通用环境下的加密流量分类技术未来发展趋势。并进一步分析了工业互联网这一特定环境下加密流量分类技术研究现状,包括公共流量数据缺乏、工业协议多样、特征提取复杂。展望了未来研究的方向,包括构建高质量数据集、优化特征提取方法、提升未知流量检测准确度。为实现加密流量精准分类以保障网络服务质量和安全防护提供借鉴和启示。

关键词: 加密流量, 未知流量检测, 深度学习, 类不平衡, 工业互联网

Abstract: With the rapid development of Internet technology, the types of network traffic have become complex and variable. At the same time, to ensure data security, a large amount of information is transmitted through encryption protocols. Under the encryption condition, the original information of the traffic is invisible, which makes traditional traffic classification methods no longer applicable. In this context, the encryption traffic classification technology has emerged. Its aim is to identify and distinguish the types and sources of encrypted traffic. Encryption traffic classification not only needs to correctly distinguish various known traffic for traffic control but also needs to identify unknown traffic that may carry malicious information for security protection. This paper introduces the research status of encryption traffic classification technology in a general environment, analyzing from three aspects: known traffic classification, unknown traffic classification, and data sets. It discusses the future development trends of encryption traffic classification technology in a general environment. Furthermore, it analyzes the research status of encryption traffic classification technology in an industrial internet environment, including the lack of public traffic data, diverse industrial protocols, and complex feature extraction. Finally, it looks forward to future research directions, including building high-quality data sets, optimizing feature extraction methods, and improving the accuracy of unknown traffic detection. To achieve precise classification of encrypted traffic and ensure network service quality and security protection, it provides references and inspirations.

Key words: encrypted traffic, unknown traffic detection, deep learning, data imbalance, industrial Internet