Traffic classification through simple statistical fingerprinting
Top Cited Papers
- 22 January 2007
- journal article
- Published by Association for Computing Machinery (ACM) in ACM SIGCOMM Computer Communication Review
- Vol. 37 (1) , 5-16
- https://doi.org/10.1145/1198255.1198257
Abstract
The classification of IP flows according to the application that generated them is at the basis of any modern network management platform. However, classical techniques such as the ones based on the analysis of transport layer or application layer information are rapidly becoming ineffective. In this paper we present a flow classification mechanism based on three simple properties of the captured IP packets: their size, inter-arrival time and arrival order. Even though these quantities have already been used in the past to define classification techniques, our contribution is based on new structures called protocol fingerprints, which express such quantities in a compact and efficient way, and on a simple classification algorithm based on normalized thresholds. Although at a very early stage of development, the proposed technique is showing promising preliminary results from the classification of a reduced set of protocolsKeywords
This publication has 11 references indexed in Scilit:
- Early application identificationPublished by Association for Computing Machinery (ACM) ,2006
- Internet traffic classification using bayesian analysis techniquesPublished by Association for Computing Machinery (ACM) ,2005
- Toward the Accurate Identification of Network ApplicationsPublished by Springer Nature ,2005
- Class-of-service mapping for QoSPublished by Association for Computing Machinery (ACM) ,2004
- Flow Clustering Using Machine Learning TechniquesPublished by Springer Nature ,2004
- An analysis of Internet chat systemsPublished by Association for Computing Machinery (ACM) ,2003
- An empirical study of real audio trafficPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Bro: a system for detecting network intruders in real-timeComputer Networks, 1999
- Wide area traffic: the failure of Poisson modelingIEEE/ACM Transactions on Networking, 1995
- Empirically derived analytic models of wide-area TCP connectionsIEEE/ACM Transactions on Networking, 1994