ENCRYPTED TRAFFIC ANALYSIS USING FLOW METADATA AND ML-BASED CLASSIFICATION
DOI:
https://doi.org/10.62643/Abstract
With over 90% of internet traffic now encrypted, traditional packet inspection tools are increasingly limited in their ability to detect threats, enforce policies, or classify applications. This paper proposes a machine learning-based approach to classify encrypted traffic using only flow-level metadata, avoiding payload inspection and preserving user privacy. We collect NetFlow and IPFIX data across multiple enterprise segments and extract 25 statistical features, including packet count, flow duration, byte-per-packet ratio, inter-packet time variance, and flow directionality. A LightGBM classifier is trained to distinguish between application types (e.g., VPN, streaming, file-sharing, malware) and behavior patterns. The model achieves 89.6% accuracy across a labeled dataset comprising 8 million flows. Feature importance analysis shows that flow duration and burst size variance are most discriminative. Use cases include real-time monitoring, anomaly detection, and policy enforcement in privacy-sensitive environments such as financial and healthcare networks. We compare our solution with DPI-based tools and JA3 fingerprinting, demonstrating improved detection of obfuscated protocols and encrypted malware. Limitations include encrypted tunneling inside VPNs and susceptibility to mimicry attacks. Our approach is non-intrusive, scalable, and well-suited for organizations adopting TLS 1.3 and QUIC protocols. The paper concludes by recommending hybrid visibility frameworks that blend metadata intelligence with host-level telemetry for encrypted traffic management.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













