Machine Learning in Networking

  • Thomas G. Robertazzi
  • Li Shi


With a significant improvement in performance and efficiency recently, machine learning techniques have been widely applied in the areas of computer vision, natural language processing, and pattern recognition. While machine learning techniques have shown their superior ability in solving many complex problems, their applications to the networking area is still at an early stage. This chapter reviews state-of-the-art machine learning applications in the networking area, with the purpose of providing some insights on existing solutions and future opportunities. An overview of machine learning begins the chapter. This is followed by discussions of the applications of machine learning techniques to traffic classification, traffic routing, and resource management, respectively.


Networking Machine learning Supervised learning Unsupervised learning Reinforcement learning Deep learning Traffic classification Traffic routing Resource management 


  1. 69.
    Benoit Claise. Specification of the ip flow information export (ipfix) protocol for the exchange of ip traffic flow information. Technical report, 2008.CrossRefGoogle Scholar
  2. 89.
    Fatih Ertam and Engin Avcı. A new approach for internet traffic classification: Ga-wk-elm. Measurement, 95: 135–142, 2017.CrossRefGoogle Scholar
  3. 170.
    Tom M. Mitchell. Machine learning. McGraw Hill series in computer science. McGraw-Hill, 1997. ISBN 978-0-07-042807-2. URL
  4. 205.
    A. L. Samuel. Some Studies in Machine Learning Using the Game of Checkers. IBM Journal of Research and Development, 3 (3): 210–229, jul 1959. ISSN 0018-8646. doi: 10.1147/rd.33.0210. URL
  5. 259.
    “Application Layer Packet Classifier for Linux”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  6. 260.
    “Datasets of Canadian Institute for Cybersecurity”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  7. 261.
    “MAWI Working Group Traffic Archive”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  8. 262.
    “WAND Group”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  9. 263.
    SNAP: Web data: Amazon reviews”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  10. 264.
    “”,, 2019. [Online]. Available: [Accessed: 23-Sep-2019].
  11. 265.
    “Database of Eurostat”, [Online]. Available: [Accessed: 23-Sep-2019].
  12. 266.
    “Open Images Dataset V5”, [Online]. Available: [Accessed: 23-Sep-2019].
  13. 267.
    Taimur Bakhshi and Bogdan Ghita. On internet traffic classification: A two-phased machine learning approach. Journal of Computer Networks and Communications, 2016.Google Scholar
  14. 268.
    Taimur Bakhshi and Bogdan Ghita. On internet traffic classification: A two-phased machine learning approach. Journal of Computer Networks and Communications, 2016.Google Scholar
  15. 269.
    Stephen D Bay, Dennis F Kibler, Michael J Pazzani, and Padhraic Smyth. The uci kdd archive of large data sets for data mining research and experimentation. SIGKDD explorations, 2 (2): 81–85, 2000.Google Scholar
  16. 270.
    David M Blei, Andrew Y Ng, and Michael I Jordan. Latent dirichlet allocation. Journal of machine Learning research, 3 (Jan): 993–1022, 2003.Google Scholar
  17. 271.
    Andreas Blenk, Patrick Kalmbach, Patrick Van Der Smagt, and Wolfgang Kellerer. Boost online virtual network embedding: Using neural networks for admission control. In 2016 12th International Conference on Network and Service Management (CNSM), pages 10–18. IEEE, 2016.Google Scholar
  18. 272.
    Andreas Blenk, Patrick Kalmbach, Johannes Zerwas, Michael Jarschel, Stefan Schmid, and Wolfgang Kellerer. Neurovine: A neural preprocessor for your virtual network embedding algorithm. In IEEE INFOCOM2018-IEEE Conference on Computer Communications, pages 405–413. IEEE, 2018.Google Scholar
  19. 273.
    Yu-ning Dong, Jia-jie Zhao, and Jiong Jin. Novel feature selection and classification of internet video traffic based on a hierarchical scheme. Computer Networks, 119: 102–111, 2017.CrossRefGoogle Scholar
  20. 274.
    Zeon Trevor Fernando, I Sumaiya Thaseen, and Ch Aswani Kumar. Network attacks identification using consistency based feature selection and self organizing maps. In 2014 First International Conference on Networks & Soft Computing (ICNSC2014), pages 162–166. IEEE, 2014.Google Scholar
  21. 275.
    Alessandro Finamore, Marco Mellia, Michela Meo, and Dario Rossi. Kiss: Stochastic packet inspection classifier for udp traffic. IEEE/ACM Transactions on Networking (TON), 18 (5): 1505–1515, 2010.CrossRefGoogle Scholar
  22. 276.
    Edward B Fowlkes and Colin L Mallows. A method for comparing two hierarchical clusterings. Journal of the American statistical association, 78 (383): 553–569, 1983.Google Scholar
  23. 277.
    Francesco Gringoli, Luca Salgarelli, Maurizio Dusi, Niccolo Cascarano, Fulvio Risso, et al. Gt: picking up the truth from the ground for internet traffic. ACM SIGCOMM Computer Communication Review, 39 (5): 12–18, 2009.Google Scholar
  24. 278.
    Patrick Haffner, Subhabrata Sen, Oliver Spatscheck, and Dongmei Wang. Acas: automated construction of application signatures. In Proceedings of the2005 ACM SIGCOMM workshop on Mining network data, pages 197–202. ACM, 2005.Google Scholar
  25. 279.
    John J Hopfield. Neural networks and physical systems with emergent collective computational abilities. Proceedings of the national academy of sciences, 79 (8): 2554–2558, 1982.Google Scholar
  26. 280.
    Tiansi Hu and Yunsi Fei. Qelar: A machine-learning-based adaptive routing protocol for energy-efficient and lifetime-extended underwater sensor networks. IEEE Transactions on Mobile Computing, 9 (6): 796–809, 2010.CrossRefGoogle Scholar
  27. 281.
    Guang-Bin Huang, Qin-Yu Zhu, and Chee-Kheong Siew. Extreme learning machine: theory and applications. Neurocomputing, 70 (1–3): 489–501, 2006.CrossRefGoogle Scholar
  28. 282.
    Victoria Huang, Gang Chen, and Qiang Fu. Effective scheduling function design in sdn through deep reinforcement learning. In ICC2019–2019 IEEE International Conference on Communications (ICC), pages 1–7. IEEE, 2019.Google Scholar
  29. 283.
    Neminath Hubballi and Mayank Swarnkar. Bitcoding: Network traffic classification through encoded bit level signatures. IEEE/ACM Transactions on Networking, (99): 1–13, 2018.Google Scholar
  30. 284.
    Lawrence Hubert and Phipps Arabie. Comparing partitions. Journal of classification, 2 (1): 193–218, 1985.CrossRefGoogle Scholar
  31. 285.
    Vijay R Konda and John N Tsitsiklis. Actor-critic algorithms. In Advances in neural information processing systems, pages 1008–1014, 2000.Google Scholar
  32. 286.
    Yann LeCun, Léon Bottou, Yoshua Bengio, Patrick Haffner, et al. Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86 (11): 2278–2324, 1998.Google Scholar
  33. 287.
    Rui Li, Xi Xiao, Shiguang Ni, Haitao Zheng, and Shutao Xia. Byte segment neural network for network traffic classification. In 2018 IEEE/ACM 26th International Symposium on Quality of Service (IWQoS), pages 1–10. IEEE, 2018.Google Scholar
  34. 288.
    Timothy P Lillicrap, Jonathan J Hunt, Alexander Pritzel, Nicolas Heess, Tom Erez, Yuval Tassa, David Silver, and Daan Wierstra. Continuous control with deep reinforcement learning. arXiv preprint arXiv:1509.02971, 2015.Google Scholar
  35. 289.
    Shih-Chun Lin, Ian F Akyildiz, Pu Wang, and Min Luo. Qos-aware adaptive routing in multi-layer hierarchical software defined networks: A reinforcement learning approach. In 2016 IEEE International Conference on Services Computing (SCC), pages 25–33. IEEE, 2016.Google Scholar
  36. 290.
    Manuel Lopez-Martin, Belen Carro, Antonio Sanchez-Esguevillas, and Jaime Lloret. Network traffic classifier with convolutional and recurrent neural networks for internet of things. IEEE Access, 5: 18042–18050, 2017.CrossRefGoogle Scholar
  37. 291.
    Mohammad Lotfollahi, Ramin Shirali Hossein Zade, Mahdi Jafari Siavoshani, and Mohammdsadegh Saberian. Deep packet: A novel approach for encrypted traffic classification using deep learning. arXiv preprint arXiv:1709.02656, 2017.Google Scholar
  38. 292.
    Andrew Moore, Denis Zuev, and Michael Crogan. Discriminators for use in flow-based classification. Technical report, 2013.Google Scholar
  39. 293.
    Andrew W Moore and Konstantina Papagiannaki. Toward the accurate identification of network applications. In International Workshop on Passive and Active Network Measurement, pages 41–54. Springer, 2005.Google Scholar
  40. 294.
    Andrew W Moore and Denis Zuev. Internet traffic classification using bayesian analysis techniques. In ACM SIGMETRICS Performance Evaluation Review, volume 33, pages 50–60. ACM, 2005.Google Scholar
  41. 295.
    Dmitry Mukhutdinov, Andrey Filchenkov, Anatoly Shalyto, and Valeriy Vyatkin. Multi-agent deep learning for simultaneous optimization for time and energy in distributed routing system. Future Generation Computer Systems, 94: 587–600, 2019.CrossRefGoogle Scholar
  42. 296.
    Tran Anh Quang Pham, Yassine Hadjadj-Aoul, and Abdelkader Outtagarts. Deep reinforcement learning based qos-aware routing in knowledge-defined networking. In International Conference on Heterogeneous Networking for Quality, Reliability, Security and Robustness, pages 14–26. Springer, 2018.Google Scholar
  43. 297.
    Lutz Prechelt. Early stopping-but when? In Neural Networks: Tricks of the trade, pages 55–69. Springer, 1998.Google Scholar
  44. 298.
    William M Rand. Objective criteria for the evaluation of clustering methods. Journal of the American Statistical association, 66 (336): 846–850, 1971.Google Scholar
  45. 299.
    Matthew Roughan, Subhabrata Sen, Oliver Spatscheck, and Nick Duffield. Class-of-service mapping for qos: a statistical signature-based approach to ip traffic classification. In Proceedings of the 4th ACM SIGCOMM conference on Internet measurement, pages 135–148. ACM, 2004.Google Scholar
  46. 300.
    Peter J Rousseeuw. Silhouettes: a graphical aid to the interpretation and validation of cluster analysis. Journal of computational and applied mathematics, 20: 53–65, 1987.Google Scholar
  47. 301.
    Gavin A Rummery and Mahesan Niranjan. On-line Q-learning using connectionist systems, volume 37. University of Cambridge, Department of Engineering Cambridge, England, 1994.Google Scholar
  48. 302.
    Saim Salman, Christopher Streiffer, Huan Chen, Theophilus Benson, and Asim Kadav. Deepconf: Automating data center network topologies management with machine learning. In Proceedings of the2018 Workshop on Network Meets AI & ML, pages 8–14. ACM, 2018.Google Scholar
  49. 303.
    John Schulman, Filip Wolski, Prafulla Dhariwal, Alec Radford, and Oleg Klimov. Proximal policy optimization algorithms. arXiv preprint arXiv:1707.06347, 2017.Google Scholar
  50. 304.
    Muhammad Shafiq, Xiangzhan Yu, Ali Kashif Bashir, Hassan Nazeer Chaudhry, and Dawei Wang. A machine learning approach for feature selection traffic classification using security analysis. The Journal of Supercomputing, 74 (10): 4867–4892, 2018.Google Scholar
  51. 305.
    David Silver, Julian Schrittwieser, Karen Simonyan, Ioannis Antonoglou, Aja Huang, Arthur Guez, Thomas Hubert, Lucas Baker, Matthew Lai, Adrian Bolton, et al. Mastering the game of go without human knowledge. Nature, 550 (7676): 354, 2017.Google Scholar
  52. 306.
    William Stallings. SNMP, SNMPv2, SNMPv3, and RMON 1 and 2. Addison-Wesley Longman Publishing Co., Inc., 1998.Google Scholar
  53. 307.
    Guanglu Sun, Teng Chen, Yangyang Su, and Chenglong Li. Internet traffic classification based on incremental support vector machines. Mobile Networks and Applications, 23 (4): 789–796, 2018.CrossRefGoogle Scholar
  54. 308.
    Haifeng Sun, Yunming Xiao, Jing Wang, Jingyu Wang, Qi Qi, Jianxin Liao, and Xiulei Liu. Common knowledge based and one-shot learning enabled multi-task traffic classification. IEEE Access, 2019.Google Scholar
  55. 309.
    Richard S Sutton and Andrew G Barto. Reinforcement learning: An introduction. MIT Press, 1988.Google Scholar
  56. 310.
    Gerald Tesauro. Reinforcement learning in autonomic computing: A manifesto and case studies. IEEE Internet Computing, 11 (1): 22–30, 2007.CrossRefGoogle Scholar
  57. 311.
    “thomasbhatia/OpenDPI”, GitHub. [Online]. Available: [Accessed: 23-Sep-2019].
  58. 312.
    Pascal Vincent, Hugo Larochelle, Yoshua Bengio, and Pierre-Antoine Manzagol. Extracting and composing robust features with denoising autoencoders. In Proceedings of the 25th international conference on Machine learning, pages 1096–1103. ACM, 2008.Google Scholar
  59. 313.
    Oriol Vinyals, Timo Ewalds, Sergey Bartunov, Petko Georgiev, Alexander Sasha Vezhnevets, Michelle Yeo, Alireza Makhzani, Heinrich Küttler, John Agapiou, Julian Schrittwieser, et al. Starcraft ii: A new challenge for reinforcement learning. arXiv preprint arXiv:1708.04782, 2017.Google Scholar
  60. 314.
    Mowei Wang, Yong Cui, Xin Wang, Shihan Xiao, and Junchen Jiang. Machine learning for networking: Workflow, advances and opportunities. IEEE Network, 32 (2): 92–99, 2018.CrossRefGoogle Scholar
  61. 315.
    Sen Wang, Jun Bi, Jianping Wu, Athanasios V Vasilakos, and Qilin Fan. Vne-td: a virtual network embedding algorithm based on temporal-difference learning. Computer Networks, 2019.Google Scholar
  62. 316.
    Yuxi Xie, Hanbo Deng, Lizhi Peng, and Zhenxiang Chen. Accurate identification of internet video traffic using byte code distribution features. In International Conference on Algorithms and Architectures for Parallel Processing, pages 46–58. Springer, 2018.Google Scholar
  63. 317.
    Zhiyuan Xu, Jian Tang, Jingsong Meng, Weiyi Zhang, Yanzhi Wang, Chi Harold Liu, and Dejun Yang. Experience-driven networking: A deep reinforcement learning based approach. In IEEE INFOCOM2018-IEEE Conference on Computer Communications, pages 1871–1879. IEEE, 2018.Google Scholar
  64. 318.
    Jinghua Yan. A survey of traffic classification validation and ground truth collection. In 2018 8th International Conference on Electronics Information and Emergency Communication (ICEIEC), pages 255–259. IEEE, 2018.Google Scholar
  65. 319.
    Lei Yu and Huan Liu. Feature selection for high-dimensional data: A fast correlation-based filter solution. In Proceedings of the 20th international conference on machine learning (ICML-03), pages 856–863, 2003.Google Scholar
  66. 320.
    Xiaochun Yun, Yipeng Wang, Yongzheng Zhang, and Yu Zhou. A semantics-aware approach to the automated network protocol identification. IEEE/ACM Transactions on Networking (TON), 24 (1): 583–595, 2016.CrossRefGoogle Scholar
  67. 321.
    Jun Zhang, Xiao Chen, Yang Xiang, Wanlei Zhou, and Jie Wu. Robust network traffic classification. IEEE/ACM Transactions on Networking (TON), 23 (4): 1257–1270, 2015.CrossRefGoogle Scholar

Copyright information

© Springer Nature Switzerland AG 2020

Authors and Affiliations

  • Thomas G. Robertazzi
    • 1
  • Li Shi
    • 1
  1. 1.Stony Brook UniversityStony BrookUSA

Personalised recommendations