Suppr超能文献

PACKETCLIP:用于网络安全推理的网络流量与语言的多模态嵌入

PACKETCLIP: multi-modal embedding of network traffic and language for cybersecurity reasoning.

作者信息

Masukawa Ryozo, Yun Sanggeon, Jeong Sungheon, Huang Wenjun, Ni Yang, Bryant Ian, Bastian Nathaniel D, Imani Mohsen

机构信息

Department of Computer Science, University of California, Irvine, Irvine, CA, United States.

Department of Electrical Engineering & Computer Science, United States Military Academy, West Point, NY, United States.

出版信息

Front Artif Intell. 2025 Jul 28;8:1593944. doi: 10.3389/frai.2025.1593944. eCollection 2025.

Abstract

Traffic classification is vital for cybersecurity, yet encrypted traffic poses significant challenges. We introduce PACKETCLIP which is a multi-modal framework combining packet data with natural language semantics through contrastive pre-training and hierarchical Graph Neural Network (GNN) reasoning. PACKETCLIP integrates semantic reasoning with efficient classification, enabling robust detection of anomalies in encrypted network flows. By aligning textual descriptions with packet behaviors, PACKETCLIP offers enhanced interpretability, scalability, and practical applicability across diverse security scenarios. With a 95% mean AUC, an 11.6% improvement over baselines, and a 92% reduction in intrusion detection training parameters, it is ideally suited for real-time anomaly detection. By bridging advanced machine-learning techniques and practical cybersecurity needs, PACKETCLIP provides a foundation for scalable, efficient, and interpretable solutions to tackle encrypted traffic classification and network intrusion detection challenges in resource-constrained environments.

摘要

流量分类对网络安全至关重要,但加密流量带来了重大挑战。我们引入了PACKETCLIP,它是一个多模态框架,通过对比预训练和分层图神经网络(GNN)推理将数据包数据与自然语言语义相结合。PACKETCLIP将语义推理与高效分类相结合,能够对加密网络流中的异常进行稳健检测。通过将文本描述与数据包行为对齐,PACKETCLIP在各种安全场景中提供了增强的可解释性、可扩展性和实际适用性。它的平均AUC为95%,比基线提高了11.6%,入侵检测训练参数减少了92%,非常适合实时异常检测。通过弥合先进的机器学习技术与实际网络安全需求之间的差距,PACKETCLIP为在资源受限环境中应对加密流量分类和网络入侵检测挑战提供了可扩展、高效且可解释的解决方案奠定了基础。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/7adb/12336109/36a0bb9cbbc3/frai-08-1593944-g0001.jpg

相似文献

1
PACKETCLIP: multi-modal embedding of network traffic and language for cybersecurity reasoning.
Front Artif Intell. 2025 Jul 28;8:1593944. doi: 10.3389/frai.2025.1593944. eCollection 2025.
2
Encrypted traffic classification encoder based on lightweight graph representation.
Sci Rep. 2025 Aug 5;15(1):28564. doi: 10.1038/s41598-025-05225-4.
4
Integrated neural network framework for multi-object detection and recognition using UAV imagery.
Front Neurorobot. 2025 Jul 30;19:1643011. doi: 10.3389/fnbot.2025.1643011. eCollection 2025.
5
Anomaly detection in encrypted network traffic using self-supervised learning.
Sci Rep. 2025 Jul 22;15(1):26585. doi: 10.1038/s41598-025-08568-0.
8
ModFus-PD: synergizing cross-modal attention and contrastive learning for enhanced multimodal diagnosis of Parkinson's disease.
Front Comput Neurosci. 2025 Jul 16;19:1604399. doi: 10.3389/fncom.2025.1604399. eCollection 2025.
9
EIM: An effective solution for improving multi-modal large language models.
PLoS One. 2025 Aug 11;20(8):e0329590. doi: 10.1371/journal.pone.0329590. eCollection 2025.

本文引用的文献

1
CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment.
Sensors (Basel). 2023 Jun 26;23(13):5941. doi: 10.3390/s23135941.
2
Catastrophic forgetting in connectionist networks.
Trends Cogn Sci. 1999 Apr;3(4):128-135. doi: 10.1016/s1364-6613(99)01294-2.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验