Back to results

Monterey, CA; Naval Postgraduate School

CLASSIFYING TCP NETWORK TRAFFIC FLOWS VIA TRAFFIC INTERACTION GRAPHS AND MACHINE LEARNING

Abstract

dc:description.abstract

Detecting malicious traffic on networks is a critical problem facing the Department of Defense. In this thesis we utilize cutting edge machine learning techniques to detect malicious network traffic. We begin with two real-world datasets. First, real internet traffic collected on the NPS Enterprise Research Network, and second, the IoT23 dataset consisting of internet of things (IoT) devices that have been infected with malware. We convert raw packet captures into TCP streams using the 5-tuple definition from RFC6146. We then apply the traffic interaction graph (TIG) framework to these flows to capture burst patterns among signed packet lengths. Finally, we train these flows on a random forest classifier (RFC), a simple convolutional neural network (CNN), and a graph convolutional network (GCN). Additionally, we simulate various attack levels by combining the two datasets at various levels (99% NPS to 1% IoT, 99-5, 90-10, and IoT23 only). In each of these models we get exceptional results in accuracy, precision, and recall. This work specifically provides a proof of concept for using the TIG framework and graph neural networks to classify TCP flows. Future work should explore model enhancement, data enrichment, or stream-lining the entire process into a real-time software package.

Degree

thesis:*
Department dc:contributor.department
Computer Science (CS)
Grantor dc:publisher
Monterey, CA; Naval Postgraduate School
Year dc:date.issued
2023

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Straughn, Matthew N.
Advisor dc:contributor.advisor
  • Barton, Armon C.

Rights

dc:rights
Statement dc:rights
  • This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10945/72396
OAI identifier oai:identifier
oai:calhoun.nps.edu:10945/72396

Chain of custody

source
Harvested from
Naval Postgraduate School
Base URL
calhoun.nps.edu/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
related terms
citation

Straughn, Matthew N.. CLASSIFYING TCP NETWORK TRAFFIC FLOWS VIA TRAFFIC INTERACTION GRAPHS AND MACHINE LEARNING. Monterey, CA; Naval Postgraduate School, 2023. https://hdl.handle.net/10945/72396