Uma Ferramenta para Classificação de Tráfego Cifrado em VPNs sem Inspeção da Carga Útil dos Pacotes

  • Enzo Basaldella CEFET-RJ
  • Dalbert Matos Mascarenhas CEFET-RJ
  • Igor Monteiro Moraes UFF

Resumo


A adoção crescente de VPNs e criptografia de ponta a ponta torna ineficazes abordagens baseadas em inspeção de carga útil dos pacotes. Este trabalho propõe e valida uma ferramenta para classificação de tráfego cifrado em VPNs, operando sobre atributos extraídos do fluxo de pacotes cifrados, sem necessidade de decifração. A solução implementa um pipeline incremental para coleta automatizada, auditoria formal, extração de 80 atributos e treinamento de modelos supervisionados. A base de dados gerada reúne mais de 25.000 janelas temporais, extraídas de 800 sessões de oito serviços em duas macrocategorias. Os classificadores atingem F1-Macro de até 98,8% na classificação binária e 97,2% na multiclasse, evidenciando a eficácia da ferramenta proposta.

Referências

Akbari, I., Salahuddin, M. A., Ven, L., Limam, N., Boutaba, R., Mathieu, B., Moteau, S., and Tuffin, S. (2021). A look behind the curtain: Traffic classification in an increasingly encrypted web. In Abstract Proceedings of the 2021 ACM SIGMETRICS / International Conference on Measurement and Modeling of Computer Systems, pages 23–24. Association for Computing Machinery.

Anderson, B. and McGrew, D. (2017). Machine learning for encrypted malware traffic classification: Accounting for noisy labels and non-stationarity. In Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pages 1723–1732. Association for Computing Machinery.

Basaldella, E., Mascarenhas, D. M., and Moraes, I. M. (2026). VPN encrypted traffic classification tool. Repositório no GitHub: [link]. Artefatos de reprodução do SBSeg 2026. Acesso em: 3 ago. 2026.

Breiman, L. (2001). Random forests. Machine Learning, 45(1):5–32.

Chen, T. and Guestrin, C. (2016). XGBoost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pages 785–794.

Cherubin, G., Jansen, R., and Troncoso, C. (2022). Online website fingerprinting: Evaluating website fingerprinting attacks on Tor in the real world. In 31st USENIX Security Symposium (USENIX Security 22), pages 753–770.

Cortes, C. and Vapnik, V. (1995). Support-vector networks. Machine Learning, 20(3):273–297.

Draper-Gil, G., Lashkari, A. H., Mamun, M. S. I., and Ghorbani, A. A. (2016). Characterization of encrypted and VPN traffic using time-related features. In Proceedings of the 2nd International Conference on Information Systems Security and Privacy (ICISSP), pages 407–414.

Griessel, A., Stephan, M., Mieth, M., Kellerer, W., and Krämer, P. (2022). RLBrowse: Generating realistic packet traces with reinforcement learning. In 2022 IEEE/IFIP Network Operations and Management Symposium (NOMS), pages 1–7.

He, H. and Garcia, E. A. (2009). Learning from imbalanced data. IEEE Transactions on Knowledge and Data Engineering, 21(9):1263–1284.

Hurley, N. and Rickard, S. (2009). Comparing measures of sparsity. IEEE Transactions on Information Theory, 55(10):4723–4741.

Kaufman, S., Rosset, S., Perlich, C., and Stitelman, O. (2012). Leakage in data mining: Formulation, detection, and avoidance. ACM Transactions on Knowledge Discovery from Data, 6(4):15:1–15:21.

Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., and Liu, T.-Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. In Advances in Neural Information Processing Systems, volume 30. Curran Associates, Inc.

Kotak, J., Yankelev, I., Bibi, I., Elovici, Y., and Shabtai, A. (2025). VPN-encrypted network traffic classification using a time-series approach. IEEE Transactions on Network and Service Management, 22(2):2225–2242.

Lotfollahi, M., Jafari Siavoshani, M., Shirali Hossein Zade, R., and Saberian, M. (2020). Deep Packet: A novel approach for encrypted traffic classification using deep learning. Soft Computing, 24(3):1999–2012.

Nguyen, T. T. T. and Armitage, G. (2008). A survey of techniques for internet traffic classification using machine learning. IEEE Communications Surveys & Tutorials, 10(4):56–76.

Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., and Duchesnay, É. (2011). Scikit-learn: Machine learning in Python. Journal of Machine Learning Research, 12:2825–2830.

Razooqi, Y. S. and Pekár, A. (2025). VPN traffic analysis: A survey on detection and application identification. IEEE Access, 13:132830–132848.

Shen, M., Ye, K., Liu, X., Zhu, L., Kang, J., Yu, S., Li, Q., and Xu, K. (2023). Machine learning-powered encrypted network traffic analysis: A comprehensive survey. IEEE Communications Surveys & Tutorials, 25(1):791–824.

Zhao, Y., Dettori, G., Boffa, M., Vassio, L., and Mellia, M. (2025). The sweet danger of sugar: Debunking representation learning for encrypted traffic classification. In Proceedings of the ACM SIGCOMM 2025 Conference, pages 296–310. Association for Computing Machinery.
Publicado
01/09/2026
BASALDELLA, Enzo; MASCARENHAS, Dalbert Matos; MORAES, Igor Monteiro. Uma Ferramenta para Classificação de Tráfego Cifrado em VPNs sem Inspeção da Carga Útil dos Pacotes. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1276-1291. DOI: https://doi.org/10.5753/sbseg.2026.27008.

Artigos mais lidos do(s) mesmo(s) autor(es)