Traffic classification through simple statistical fingerprinting.

被引:272
作者
Crotti, Manuel [1 ]
Dusi, Maurizio [1 ]
Gringoli, Francesco [1 ]
Salgarelli, Luca [1 ]
机构
[1] Univ Brescia, DEA, I-25121 Brescia, Italy
关键词
traffic classification; transport layer;
D O I
10.1145/1198255.1198257
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The classification of IP flows according to the application that generated them is at the basis of any modern network management platform. However, classical techniques such as the ones based on the analysis of transport layer or application layer information are rapidly becoming ineffective. In this paper we present a flow classification mechanism based on three simple properties of the captured IP packets: their size, inter-arrival time and arrival order. Even though these quantities have already been used in the past to define classification techniques, our contribution is based on new structures called protocol fingerprints, which express such quantities in a compact and efficient way, and on a simple classification algorithm based on normalized thresholds. Although at a very early stage of development, the proposed technique is showing promising preliminary results from the classification of a reduced set of protocols.
引用
收藏
页码:5 / 16
页数:12
相关论文
共 15 条
  • [1] [Anonymous], SIGCOMM
  • [2] [Anonymous], SIGMETRICS 05
  • [3] Bernaille Laurent, 2006, P ACM CONEXT
  • [4] DEWES C, 2003, IMC 03, P51
  • [5] HERNANDEZCAMPOS F, 2003, COMPUTING SCI ST JUL, V35
  • [6] McGregor A, 2004, LECT NOTES COMPUT SC, V3015, P205
  • [7] Mena A., 2000, Proceedings IEEE INFOCOM 2000. Conference on Computer Communications. Nineteenth Annual Joint Conference of the IEEE Computer and Communications Societies (Cat. No.00CH37064), P101, DOI 10.1109/INFCOM.2000.832178
  • [8] Toward the accurate identification of network applications
    Moore, AW
    Papagiannaki, K
    [J]. PASSIVE AND ACTIVE NETWORK MEASUREMENT, PROCEEDINGS, 2005, 3431 : 41 - 54
  • [9] MOORE D, 2001, LISA 01, P133
  • [10] EMPIRICALLY DERIVED ANALYTIC MODELS OF WIDE-AREA TCP CONNECTIONS
    PAXSON, V
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 1994, 2 (04) : 316 - 336