[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125297-en":3,"doc-seo-125297-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125297,1374391974468,"Eden","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Machine Learning for Network Traffic Classification Under Labeled Data and Training Time Constraints","This thesis investigates using machine learning, including deep learning, for network traffic classification under practical constraints: limited labeled data and insufficient training time for models trained from scratch. Network traffic classification is central to network security, network management, and application identification, yet labeling is costly and time-intensive. The work develops a semi-supervised method leveraging positively labeled and unlabeled data via bootstrap aggregation and tree-based classifiers to classify unlabeled flows and detect zero-day encrypted messaging applications without training data. It also explores deep transfer learning by converting network flows into grayscale traffic images and transferring from state-of-the-art computer vision models to accelerate training.","MACHINE LEARNING FOR NETWORK TRAFFIC CLASSIFICATION UNDER LABELED DATA AND TRAINING TIME CONSTRAINTS  \nby  \nJason P. Hussey  \n© Copyright by Jason P. Hussey, 2023  \nAll Rights Reserved  \nA thesis submitted to the Faculty and the Board of Trustees of the Colorado School of Mines in partial fulfillment of the requirements for the degree of Doctor of Philosophy (Computer Science) .  \nGolden, Colorado  \nDate    \nSigned:   Jason P. Hussey  \nSigned:    \nDr. Tracy K. Camp Thesis Advisor  \nSigned:    \nDr. Kerri A. Stone Thesis Advisor  \nGolden, Colorado  \nDate    \nSigned:    \nDr. Iris Bahar  \nDepartment Head and Professor Department of Computer Science  \nABSTRACT  \nThis thesis investigates using machine learning (including deep learning) for network traffic classification when constrained by too little labeled data or insufficient time to train models from scratch. Network traffic classification is essential in network security, network management, and application identification. Labeling network traffic data, however, is often time-consuming and expensive, which limits the amount of labeled data available for training machine learning models.  \nThis thesis investigates using a semi-supervised learning approach that leverages positively labeled and unlabeled data to improve classification performance when faced with a lack of labeled data. The method uses a combination of bootstrap aggregation and tree-based classifiers  \nto classify unlabeled network traffic flows from the same class successfully. This same semi-supervised learning approach also successfully detects zero-day (i.e., never before seen) encrypted messaging applications for which no training data is available.  \nAdditionally, this thesis investigates using deep transfer learning from a state-of-the-art computer vision model for network traffic image classification. By representing network traffic flows as grayscale network traffic images, highly sophisticated image classification models can transfer to the task of network traffic classification. Using these advanced models as a source for training dramatically enhances the speed at which new models can train, addressing the constraint of having too little time for training. To investigate whether deep transfer learning is successful in network traffic image classification, this work used our network flow capture system (which creates a volume of unlabeled data) and commercial appliances (to turn the unlabeled dataset into a real-world labeled dataset) .  \nExperimental results in this thesis demonstrate that the semi-supervised learning technique of positive and unlabeled learning is highly effective at detecting hidden positives amongst unlabeled data. Furthermore, this thesis shows that representing network traffic flows as grayscale images allows state-of-the-art image classification models (e.g., ResNet) to transfer to the domain of network traffic classification effectively.  \nTABLE OF CONTENTS  \nABSTRACT .............................................. iii  \nLIST OF FIGURES ......................................... viii  \nLIST OF TABLES ........................................... x  \nACKNOWLEDGMENTS ...................................... xii  \nDEDICATION ............................................ xiii  \nCHAPTER 1 INTRODUCTION ................................... 1  \nCHAPTER 2 NETWORK TRAFFIC FLOW COLLECTION FOR MOBILE APPLICATIONS AND CAMPUS AREA NETWORK WI-FI .......... 5  \n2.1 Introduction .......................................... 5  \n2.2 Mobile Application and Campus Wi-Fi Data Collection ................. 6  \n2.2.1 Android Application Traffic Capture ........................ 6  \n2.2.2 Campus Wi-Fi Capture ............................... 8  \n2.3 Experimental Design ..................................... 9  \n2.4 Data Representation .................................... 10  \n2.5 Acknowledgment ...................................... 11  \nCHAPTER 3 POSITIVE AND UNLABELED LEARNING FOR MOBILE APPLICATION TRAFFIC CLASSIFI","cbCaiaiBIYVwrCb1","https://ap.wps.com/l/cbCaiaiBIYVwrCb1","pdf",2317821,1,126,"English","en",105,"# Abstract\n# Chapter 1 Introduction\n# Chapter 2 Network Traffic Flow Collection for Mobile Applications and Campus Area Network Wi-Fi\n## 2.2 Mobile Application and Campus Wi-Fi Data Collection\n## 2.4 Data Representation\n# Chapter 3 Positive and Unlabeled Learning for Mobile Application Traffic Classification\n## 3.6 Positive and Unlabeled (PU) Learning\n## 3.9 Related Work\n# Chapter 4 Generalizing Machine Learning Models for Zero-Day Encrypted Messaging Applications","[{\"question\":\"What challenge does this thesis address in network traffic classification?\",\"answer\":\"It addresses the difficulty of training accurate classifiers when labeled traffic data is scarce and when there is not enough time to train models from scratch.\"},{\"question\":\"How does the thesis improve classification with limited labeled data?\",\"answer\":\"It uses a semi-supervised approach based on positive and unlabeled learning, combining bootstrap aggregation with tree-based classifiers to learn from positively labeled and unlabeled flows.\"},{\"question\":\"How does the thesis handle zero-day encrypted messaging applications?\",\"answer\":\"It demonstrates that the positive and unlabeled learning approach can detect zero-day encrypted messaging applications even when no training data is available.\"}]","Machine Learning for Network Traffic Classification Under Labeled Data and Training Time Constraints | PDF",1785898049,318,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-for-network-traffic-classification-under-labeled-data-and-training-time-constraints","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-for-network-traffic-classification-under-labeled-data-and-training-time-constraints/125297/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What challenge does this thesis address in network traffic classification?","Question",{"text":75,"@type":76},"It addresses the difficulty of training accurate classifiers when labeled traffic data is scarce and when there is not enough time to train models from scratch.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the thesis improve classification with limited labeled data?",{"text":80,"@type":76},"It uses a semi-supervised approach based on positive and unlabeled learning, combining bootstrap aggregation with tree-based classifiers to learn from positively labeled and unlabeled flows.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the thesis handle zero-day encrypted messaging applications?",{"text":84,"@type":76},"It demonstrates that the positive and unlabeled learning approach can detect zero-day encrypted messaging applications even when no training data is available.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]