A markovian signature-based approach to IP traffic classification
- 12 June 2007
- proceedings article
- Published by Association for Computing Machinery (ACM)
Abstract
International audienceIn this paper we present a real-time automatic process to traffic classification and to the detection of abnormal behaviors in IP traffic. The proposed method aims to detect anomalies in the traffic associated to a particular service, or to automatically recognize the service associated to a given sequence of packets at the transport layer. Service classification is becoming a central issue because of the emergence of new services (P2P, VoIP, Streaming video, etc...) which raises new challenges in resource reservation, pricing, network monitoring, etc... In order to identify a specific signature to an application, we first of all model the sequence of its packets at the transport layer by means of a first order Markov chain. Then, we decide which service should be associated to any new sequence by means of standard decision techniques (Maximum Likelihood criterion, Neyman-Pearson test). The evaluation of our automatic recognition procedure using live GPRS Orange France traffic traces demonstrates the feasibility and the excellent performance of this approachKeywords
This publication has 10 references indexed in Scilit:
- Early application identificationPublished by Association for Computing Machinery (ACM) ,2006
- Internet traffic classification using bayesian analysis techniquesPublished by Association for Computing Machinery (ACM) ,2005
- Is P2P dying or just hiding?Published by Institute of Electrical and Electronics Engineers (IEEE) ,2005
- Toward the Accurate Identification of Network ApplicationsPublished by Springer Nature ,2005
- Class-of-service mapping for QoSPublished by Association for Computing Machinery (ACM) ,2004
- Accurate, scalable in-network identification of p2p traffic using application signaturesPublished by Association for Computing Machinery (ACM) ,2004
- An analysis of Internet chat systemsPublished by Association for Computing Machinery (ACM) ,2003
- HTTP/TCP connection and flow characteristicsPerformance Evaluation, 2000
- On the converse theorem in statistical hypothesis testing for Markov chainsIEEE Transactions on Information Theory, 1993
- An Intrusion-Detection ModelIEEE Transactions on Software Engineering, 1987