通过远程主机的离散性识别类bt P2P流量

W. Cheng, J. Gong, W. Ding
{"title":"通过远程主机的离散性识别类bt P2P流量","authors":"W. Cheng, J. Gong, W. Ding","doi":"10.1109/LCN.2007.69","DOIUrl":null,"url":null,"abstract":"By analyzing application protocols and traffic, we find that the most striking distinguish between BitTorrent (BT)-like peer-to-peer (P2P) applications' traffic and traditional as well as other P2P (such as Skype) applications' traffic of a single user may be the dissimilarity in the distribution of remote hosts involved. Therefore, we propose a method based on discreteness of remote hosts (RHD) to identify BT-like traffic. In this method, traffic for each user host in a stub network need be monitored at the border of the stub network and classified into flows. At intervals concurrent TCP and UDP flows for a single host should be grouped respectively by what stub network the remote host of each flow belongs to, and then calculate instant RHDs for TCP and UDP flows respectively. For any user host, if the sum of two average RHDs for a period of time exceeds specific threshold, then we can deduce that the host has used BT-like P2P application. The method proposed here is a simple traffic characteristic-based traffic classification method. It is more suitable for identifying protean BT-like P2P application than usual content-based methods such as those based on port numbers or application signatures. Experiments results reveal that our method can effectively recognize BT-like traffic and may be particularly appropriate for use to restrict BT-like traffic during working hours if needed.","PeriodicalId":333233,"journal":{"name":"32nd IEEE Conference on Local Computer Networks (LCN 2007)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-10-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"Identifying BT-like P2P Traffic by the Discreteness of Remote Hosts\",\"authors\":\"W. Cheng, J. Gong, W. Ding\",\"doi\":\"10.1109/LCN.2007.69\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"By analyzing application protocols and traffic, we find that the most striking distinguish between BitTorrent (BT)-like peer-to-peer (P2P) applications' traffic and traditional as well as other P2P (such as Skype) applications' traffic of a single user may be the dissimilarity in the distribution of remote hosts involved. Therefore, we propose a method based on discreteness of remote hosts (RHD) to identify BT-like traffic. In this method, traffic for each user host in a stub network need be monitored at the border of the stub network and classified into flows. At intervals concurrent TCP and UDP flows for a single host should be grouped respectively by what stub network the remote host of each flow belongs to, and then calculate instant RHDs for TCP and UDP flows respectively. For any user host, if the sum of two average RHDs for a period of time exceeds specific threshold, then we can deduce that the host has used BT-like P2P application. The method proposed here is a simple traffic characteristic-based traffic classification method. It is more suitable for identifying protean BT-like P2P application than usual content-based methods such as those based on port numbers or application signatures. Experiments results reveal that our method can effectively recognize BT-like traffic and may be particularly appropriate for use to restrict BT-like traffic during working hours if needed.\",\"PeriodicalId\":333233,\"journal\":{\"name\":\"32nd IEEE Conference on Local Computer Networks (LCN 2007)\",\"volume\":\"46 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-10-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"32nd IEEE Conference on Local Computer Networks (LCN 2007)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/LCN.2007.69\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"32nd IEEE Conference on Local Computer Networks (LCN 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/LCN.2007.69","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

摘要

通过分析应用协议和流量,我们发现类似BitTorrent (BT)的P2P应用程序的流量与传统以及其他P2P(如Skype)应用程序的单用户流量之间最显著的区别可能是所涉及的远程主机分布的不同。因此,我们提出了一种基于远程主机离散性(RHD)的方法来识别类bt流量。在这种方法中,需要在stub网络的边界对stub网络中每个用户主机的流量进行监控,并对其进行流分类。每隔一段时间,单个主机的并发TCP和UDP流应根据每个流所属的远端主机所属的存根网络分别分组,然后分别计算TCP和UDP流的即时rhd。对于任意用户主机,如果一段时间内两个平均rhd之和超过特定阈值,则可以推断该主机使用了类bt P2P应用。本文提出的方法是一种简单的基于流量特征的流量分类方法。它比通常基于内容的方法(如基于端口号或应用签名的方法)更适合于识别多变的bt类P2P应用。实验结果表明,该方法可以有效识别类bt流量,特别适合在工作时间限制类bt流量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Identifying BT-like P2P Traffic by the Discreteness of Remote Hosts
By analyzing application protocols and traffic, we find that the most striking distinguish between BitTorrent (BT)-like peer-to-peer (P2P) applications' traffic and traditional as well as other P2P (such as Skype) applications' traffic of a single user may be the dissimilarity in the distribution of remote hosts involved. Therefore, we propose a method based on discreteness of remote hosts (RHD) to identify BT-like traffic. In this method, traffic for each user host in a stub network need be monitored at the border of the stub network and classified into flows. At intervals concurrent TCP and UDP flows for a single host should be grouped respectively by what stub network the remote host of each flow belongs to, and then calculate instant RHDs for TCP and UDP flows respectively. For any user host, if the sum of two average RHDs for a period of time exceeds specific threshold, then we can deduce that the host has used BT-like P2P application. The method proposed here is a simple traffic characteristic-based traffic classification method. It is more suitable for identifying protean BT-like P2P application than usual content-based methods such as those based on port numbers or application signatures. Experiments results reveal that our method can effectively recognize BT-like traffic and may be particularly appropriate for use to restrict BT-like traffic during working hours if needed.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信