In [1]:
import pandas as pd
import numpy as np
from EIMTC.preprocessing import OneHotEncoderEIMTC
from EIMTC.selection import train_test_split
from EIMTC.metrics import classification_report
from EIMTC.models import M1CNN
from EIMTC.plugins.stnn import STNN
from EIMTC.plugins.n_bytes import NBytes

In [2]:
filepath = './data/out.csv'
feature_columns = [
    'udps.n_bytes',
    'udps.stnn_image',
    'udps.src2dst_mean_packet_relative_times',
    'udps.src2dst_stddev_packet_relative_times',
    'udps.dst2src_mean_packet_relative_times',
    'udps.dst2src_stddev_packet_relative_times',
    'udps.src2dst_small_packet_payload_ratio',
    'udps.dst2src_small_packet_payload_ratio', 
    'udps.mean_req_res_time_diff', 
    'udps.stddev_req_res_time_diff',
]
label_columns = [ 'os', 'browser']
columns_to_load = feature_columns + label_columns
df = pd.read_csv(filepath, usecols=columns_to_load)
df

Unnamed: 0,udps.src2dst_mean_packet_relative_times,udps.src2dst_stddev_packet_relative_times,udps.dst2src_mean_packet_relative_times,udps.dst2src_stddev_packet_relative_times,udps.src2dst_small_packet_payload_ratio,udps.dst2src_small_packet_payload_ratio,udps.mean_req_res_time_diff,udps.stddev_req_res_time_diff,udps.n_bytes,udps.stnn_image,os,browser
0,68217.705882,93458.486452,87534.812500,100890.122630,0.705882,0.687500,10448.869565,18445.574983,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 44999.0, 2271.65, 10057.03, 4.1294065, ...",Linux,Firefox
1,10871.857143,14434.607342,13830.545455,14977.590839,0.642857,0.636364,1893.125000,7257.475645,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 30001.0, 1510.45, 6706.0234, 4.129393, ...",Linux,Chrome
2,7244.140339,2399.465091,7935.080440,1694.896551,0.986601,0.002894,22.627208,701.521796,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 42.0, 6.5, 12.9147, 2.0129657, 66.0, 14...",OSX,Safari
3,30937.515152,42700.413707,17454.606061,35918.535945,0.909091,0.303030,2323.280000,4149.695406,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 199.0, 22.2, 48.05545, 2.7663713, 54.0,...",Windows,Firefox
4,1276.000000,3186.510387,178.000000,51.393904,0.777778,0.333333,30.400000,39.200000,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 9982.0, 685.73334, 2571.9824, 3.4732416...",Linux,Chrome
...,...,...,...,...,...,...,...,...,...,...,...,...
20628,912.230769,588.396407,7131.400000,18788.226820,0.538462,0.200000,3733.882353,14474.046838,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 218.0, 80.2, 88.81536, 0.50415426, 54.0...",Windows,IExplorer
20629,143743.772727,98407.578953,147299.023256,97197.124561,0.427273,0.503876,3762.427083,8850.413582,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 330.0, 70.2, 80.19883, 1.7531445, 54.0,...",Windows,IExplorer
20630,43775.761905,78525.268730,60875.565217,93239.607571,0.666667,0.652174,8284.586207,16987.559358,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 67.0, 9.25, 19.191212, 2.4089437, 66.0,...",Linux,Firefox
20631,21599.112903,39147.910774,16890.575758,34277.449852,0.887097,0.242424,1110.867925,3061.737502,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 78.0, 11.9, 28.0674, 1.9586945, 66.0, 1...",Linux,Firefox


In [3]:
def preprocessing(df):
    df = df.dropna().copy()
    enc = OneHotEncoderEIMTC()
    df['browser_ohc'] = list(enc.fit_transform(df['browser']).toarray())
    NBytes.preprocess(dataframe=df)
    STNN.preprocess(dataframe=df)

    return df

In [4]:
df = preprocessing(df)
df

Unnamed: 0,udps.src2dst_mean_packet_relative_times,udps.src2dst_stddev_packet_relative_times,udps.dst2src_mean_packet_relative_times,udps.dst2src_stddev_packet_relative_times,udps.src2dst_small_packet_payload_ratio,udps.dst2src_small_packet_payload_ratio,udps.mean_req_res_time_diff,udps.stddev_req_res_time_diff,udps.n_bytes,udps.stnn_image,os,browser,browser_ohc
0,68217.705882,93458.486452,87534.812500,100890.122630,0.705882,0.687500,10448.869565,18445.574983,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 44999.0, 2271.65, 10057.03, 4.1294065, ...",Linux,Firefox,"[0.0, 1.0, 0.0, 0.0]"
1,10871.857143,14434.607342,13830.545455,14977.590839,0.642857,0.636364,1893.125000,7257.475645,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 30001.0, 1510.45, 6706.0234, 4.129393, ...",Linux,Chrome,"[1.0, 0.0, 0.0, 0.0]"
2,7244.140339,2399.465091,7935.080440,1694.896551,0.986601,0.002894,22.627208,701.521796,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 42.0, 6.5, 12.9147, 2.0129657, 66.0, 14...",OSX,Safari,"[0.0, 0.0, 0.0, 1.0]"
3,30937.515152,42700.413707,17454.606061,35918.535945,0.909091,0.303030,2323.280000,4149.695406,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 199.0, 22.2, 48.05545, 2.7663713, 54.0,...",Windows,Firefox,"[0.0, 1.0, 0.0, 0.0]"
4,1276.000000,3186.510387,178.000000,51.393904,0.777778,0.333333,30.400000,39.200000,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 9982.0, 685.73334, 2571.9824, 3.4732416...",Linux,Chrome,"[1.0, 0.0, 0.0, 0.0]"
...,...,...,...,...,...,...,...,...,...,...,...,...,...
20628,912.230769,588.396407,7131.400000,18788.226820,0.538462,0.200000,3733.882353,14474.046838,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 218.0, 80.2, 88.81536, 0.50415426, 54.0...",Windows,IExplorer,"[0.0, 0.0, 1.0, 0.0]"
20629,143743.772727,98407.578953,147299.023256,97197.124561,0.427273,0.503876,3762.427083,8850.413582,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 330.0, 70.2, 80.19883, 1.7531445, 54.0,...",Windows,IExplorer,"[0.0, 0.0, 1.0, 0.0]"
20630,43775.761905,78525.268730,60875.565217,93239.607571,0.666667,0.652174,8284.586207,16987.559358,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 67.0, 9.25, 19.191212, 2.4089437, 66.0,...",Linux,Firefox,"[0.0, 1.0, 0.0, 0.0]"
20631,21599.112903,39147.910774,16890.575758,34277.449852,0.887097,0.242424,1110.867925,3061.737502,"[0.08627450980392157, 0.011764705882352941, 0....","[[0.0, 78.0, 11.9, 28.0674, 1.9586945, 66.0, 1...",Linux,Firefox,"[0.0, 1.0, 0.0, 0.0]"


In [6]:
n_bytes_features = np.stack(df[feature_columns[0]].values)[:,:200]
stnn_features = np.stack(df[feature_columns[1]].apply(np.reshape, newshape=70).values)
new_features = np.stack(df[feature_columns[2:]].values)

features = np.concatenate([n_bytes_features, stnn_features, new_features], axis=1)

In [8]:
x_train, x_test, y_train, y_test = train_test_split(features, df['browser_ohc'].values, 
    test_size=0.25,
    stratify=df['browser'].values,
    random_state=42)

In [11]:
n_classes = len(df['browser'].unique())
model = M1CNN(payload_size=len(features[0]), n_classes=n_classes)
print(len(features[0]), n_classes)

278 4


In [12]:
epochs = 10
batch_size = 128
model.compile(
    optimizer='adam',
    loss='categorical_crossentropy',
    metrics=['accuracy']
)
model.fit(
    np.stack(x_train), 
    np.stack(y_train), 
    epochs=epochs, 
    batch_size=batch_size, 
    use_multiprocessing=True,
    workers=4,
    verbose=2
)

Epoch 1/10
121/121 - 1s - loss: 6430.7783 - accuracy: 0.3552
Epoch 2/10
121/121 - 1s - loss: 4.5288 - accuracy: 0.5467
Epoch 3/10
121/121 - 1s - loss: 1.8676 - accuracy: 0.7518
Epoch 4/10
121/121 - 1s - loss: 1.1520 - accuracy: 0.8015
Epoch 5/10
121/121 - 1s - loss: 0.5527 - accuracy: 0.8305
Epoch 6/10
121/121 - 1s - loss: 0.4657 - accuracy: 0.8555
Epoch 7/10
121/121 - 1s - loss: 0.3951 - accuracy: 0.8779
Epoch 8/10
121/121 - 1s - loss: 0.3580 - accuracy: 0.8932
Epoch 9/10
121/121 - 1s - loss: 0.3363 - accuracy: 0.8985
Epoch 10/10
121/121 - 1s - loss: 0.3208 - accuracy: 0.9016


<tensorflow.python.keras.callbacks.History at 0x1ae401bb390>

In [13]:
predictions = model.model.predict(np.stack(x_test))
predictions = np.argmax(predictions, axis=1)
y_test_true = np.argmax(np.stack(y_test), axis=1)

report = classification_report(y_test_true, predictions)
report

'              precision    recall  f1-score   support\n\n           0       0.79      0.85      0.82      1265\n           1       0.91      0.84      0.87      1465\n           2       0.95      0.95      0.95      1781\n           3       0.97      0.99      0.98       647\n\n    accuracy                           0.90      5158\n   macro avg       0.90      0.91      0.90      5158\nweighted avg       0.90      0.90      0.90      5158\n'

In [33]:
with open('m1cnn+features_boa2016_browser_report.txt', "w+") as f:
    f.write(report)