Publication | Closed Access
Traffic classification through simple statistical fingerprinting
394
Citations
13
References
2007
Year
Internet Traffic AnalysisEngineeringEncrypted TrafficInformation ForensicsHardware SecurityData ScienceData MiningPattern RecognitionOw Classification MechanismInternet Of ThingsNetwork Traffic MeasurementTransportation EngineeringProtocol FingerprintsComputer EngineeringComputer ScienceTraffic MonitoringSignal ProcessingTraffic ClassificationCryptographyNetwork Communication ProtocolInternet ProtocolNormalized ThresholdsTransport Layer
Classifying IP flows by application is essential for modern network management, yet traditional transport- or application-layer methods are rapidly losing effectiveness. This study introduces a flow classification method that relies on packet size, inter-arrival time, and arrival order. The method constructs compact protocol fingerprints from these metrics and applies a simple threshold-based classifier. Early experiments on a limited protocol set demonstrate promising preliminary classification performance.
The classification of IP ows according to the application that generated them is at the basis of any modern network management platform. However, classical techniques such as the ones based on the analysis of transport layer or application layer information are rapidly becoming ineffective. In this paper we present a ow classification mechanism based on three simple properties of the captured IP packets: their size, inter-arrival time and arrival order. Even though these quantities have already been used in the past to define classification techniques, our contribution is based on new structures called protocol fingerprints, which express such quantities in a compact and efficient way, and on a simple classification algorithm based on normalized thresholds. Although at a very early stage of development, the proposed technique is showing promising preliminary results from the classification of a reduced set of protocols.
| Year | Citations | |
|---|---|---|
Page 1
Page 1