Service Identification by Packet Inspection Based on N-grams in Multiple Connections

Masaki Hara, Shinnosuke Nirasawa, A. Nakao, M. Oguchi, Shu Yamamoto, Saneyasu Yamaguchi
{"title":"Service Identification by Packet Inspection Based on N-grams in Multiple Connections","authors":"Masaki Hara, Shinnosuke Nirasawa, A. Nakao, M. Oguchi, Shu Yamamoto, Saneyasu Yamaguchi","doi":"10.1109/CANDAR.2016.0123","DOIUrl":null,"url":null,"abstract":"Identifying the service of traffic by given IP network flows is essential for various purposes, such as management of QoS and avoiding security issues. Typical methods for this are identification based on its IP addresses and port numbers. However, the achieved accuracies of these method are not sufficient, then improving these methods is required. Deep Packet Inspection (DPI) is one of the most effective methods for improving accuracy of identification. In this paper, we explore a method for identifying the service of flow. We propose an identifying method based on DPI which covers multiple connections in a service. Then, we present performance evaluation and demonstrate that our method can suitably identify service from given network flows.","PeriodicalId":322499,"journal":{"name":"2016 Fourth International Symposium on Computing and Networking (CANDAR)","volume":"11 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Fourth International Symposium on Computing and Networking (CANDAR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CANDAR.2016.0123","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Identifying the service of traffic by given IP network flows is essential for various purposes, such as management of QoS and avoiding security issues. Typical methods for this are identification based on its IP addresses and port numbers. However, the achieved accuracies of these method are not sufficient, then improving these methods is required. Deep Packet Inspection (DPI) is one of the most effective methods for improving accuracy of identification. In this paper, we explore a method for identifying the service of flow. We propose an identifying method based on DPI which covers multiple connections in a service. Then, we present performance evaluation and demonstrate that our method can suitably identify service from given network flows.
基于N-grams的多连接报文检测服务识别
通过给定的IP网络流识别流量的服务对于各种目的(例如QoS管理和避免安全问题)都是必不可少的。典型的方法是基于其IP地址和端口号进行识别。然而,这些方法所达到的精度还不够,因此需要对这些方法进行改进。深度包检测(Deep Packet Inspection, DPI)是提高识别准确率的最有效方法之一。本文探讨了一种识别流服务的方法。提出了一种基于DPI的识别方法,该方法可以覆盖服务中的多个连接。然后,我们给出了性能评估,并证明了我们的方法可以适当地从给定的网络流中识别服务。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信