Packet classification in co-mingled traffic streams

Siddharth Maru, T. Brown
{"title":"Packet classification in co-mingled traffic streams","authors":"Siddharth Maru, T. Brown","doi":"10.1109/NPSEC.2009.5342251","DOIUrl":null,"url":null,"abstract":"This paper considers the problem of packet classification in a co-mingled traffic stream. Given an encrypted co-mingled stream consisting of different protocol flows originating from different sources; we investigate if it is possible to assign packets to their respective sources and identify the protocol for each source. Encryption makes it difficult to obtain any information from packet headers or payloads. Consequently the only information available to an observer is the packet size, arrival times, direction and power levels. This paper presents a statistical approach that analyses the sizes and power levels of packets belonging to each protocol and uses this information to classify the packets in the co-mingled stream. Results are presented for the classification of a co-mingled stream of upto five different protocols. The results show that it is possible to efficiently classify packets based on sizes, direction and power levels. We see that packets belonging to the HTTP protocol are easiest to classify whereas those belonging to the FTP and IMAP protocols are difficult to separate when co-mingled with each other.","PeriodicalId":307178,"journal":{"name":"2009 5th IEEE Workshop on Secure Network Protocols","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 5th IEEE Workshop on Secure Network Protocols","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NPSEC.2009.5342251","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

This paper considers the problem of packet classification in a co-mingled traffic stream. Given an encrypted co-mingled stream consisting of different protocol flows originating from different sources; we investigate if it is possible to assign packets to their respective sources and identify the protocol for each source. Encryption makes it difficult to obtain any information from packet headers or payloads. Consequently the only information available to an observer is the packet size, arrival times, direction and power levels. This paper presents a statistical approach that analyses the sizes and power levels of packets belonging to each protocol and uses this information to classify the packets in the co-mingled stream. Results are presented for the classification of a co-mingled stream of upto five different protocols. The results show that it is possible to efficiently classify packets based on sizes, direction and power levels. We see that packets belonging to the HTTP protocol are easiest to classify whereas those belonging to the FTP and IMAP protocols are difficult to separate when co-mingled with each other.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
混合流中的包分类
研究了混合流中的分组分类问题。给定一个由来自不同来源的不同协议流组成的加密混合流;我们研究是否有可能将数据包分配到各自的源,并确定每个源的协议。加密使得从包头或有效负载中获取任何信息变得困难。因此,观察者唯一能得到的信息是数据包的大小、到达时间、方向和功率水平。本文提出了一种统计方法,分析属于每种协议的数据包的大小和功率级别,并使用这些信息对混合流中的数据包进行分类。结果提出了一个混合流的分类多达五种不同的协议。结果表明,基于大小、方向和功率等级对数据包进行有效分类是可能的。我们看到,属于HTTP协议的数据包最容易分类,而属于FTP和IMAP协议的数据包在相互混合时很难分离。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Information game of public firewall rules On key agreement in wireless sensor networks based on radio transmission properties Project Bloom: Empowering the security research community through data products and computing Packet classification in co-mingled traffic streams Cryptographic protocols to fight sinkhole attacks on tree-based routing in Wireless Sensor Networks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1