2014 · 187 citations · 18 references
Hardware SecurityInternet SecurityInternet Traffic AnalysisEngineeringStochastic FingerprintsEncrypted TrafficInformation SecurityData PrivacyInformation ForensicsComputer ScienceApplication DiscriminationNetwork Traffic MeasurementApplication TrafficMarkov ChainData SecurityCryptographyNetwork Security
In this paper, we propose stochastic fingerprints for application traffic flows conveyed in Secure Socket Layer/Transport Layer Security (SSL/TLS) sessions. The fingerprints are based on first-order homogeneous Markov chains for which we identify the parameters from observed training application traces. As the fingerprint parameters of chosen applications considerably differ, the method results in a very good accuracy of application discrimination and provides a possibility of detecting abnormal SSL/TLS sessions. Our analysis of the results reveals that obtaining application discrimination mainly comes from incorrect implementation practice, the misuse of the SSL/TLS protocol, various server configurations, and the application nature.
18
Thomas Karagiannis, Konstantina Papagiannaki, Michalis Faloutsos · 2005 · 998 citations
R.A. Fisher and the making of maximum likelihood 1912-1922
John Aldrich · Statistical Science · 1997 · 612 citations · Full text