混合流中的包分类

Siddharth Maru, T. Brown
{"title":"混合流中的包分类","authors":"Siddharth Maru, T. Brown","doi":"10.1109/NPSEC.2009.5342251","DOIUrl":null,"url":null,"abstract":"This paper considers the problem of packet classification in a co-mingled traffic stream. Given an encrypted co-mingled stream consisting of different protocol flows originating from different sources; we investigate if it is possible to assign packets to their respective sources and identify the protocol for each source. Encryption makes it difficult to obtain any information from packet headers or payloads. Consequently the only information available to an observer is the packet size, arrival times, direction and power levels. This paper presents a statistical approach that analyses the sizes and power levels of packets belonging to each protocol and uses this information to classify the packets in the co-mingled stream. Results are presented for the classification of a co-mingled stream of upto five different protocols. The results show that it is possible to efficiently classify packets based on sizes, direction and power levels. We see that packets belonging to the HTTP protocol are easiest to classify whereas those belonging to the FTP and IMAP protocols are difficult to separate when co-mingled with each other.","PeriodicalId":307178,"journal":{"name":"2009 5th IEEE Workshop on Secure Network Protocols","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Packet classification in co-mingled traffic streams\",\"authors\":\"Siddharth Maru, T. Brown\",\"doi\":\"10.1109/NPSEC.2009.5342251\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper considers the problem of packet classification in a co-mingled traffic stream. Given an encrypted co-mingled stream consisting of different protocol flows originating from different sources; we investigate if it is possible to assign packets to their respective sources and identify the protocol for each source. Encryption makes it difficult to obtain any information from packet headers or payloads. Consequently the only information available to an observer is the packet size, arrival times, direction and power levels. This paper presents a statistical approach that analyses the sizes and power levels of packets belonging to each protocol and uses this information to classify the packets in the co-mingled stream. Results are presented for the classification of a co-mingled stream of upto five different protocols. The results show that it is possible to efficiently classify packets based on sizes, direction and power levels. We see that packets belonging to the HTTP protocol are easiest to classify whereas those belonging to the FTP and IMAP protocols are difficult to separate when co-mingled with each other.\",\"PeriodicalId\":307178,\"journal\":{\"name\":\"2009 5th IEEE Workshop on Secure Network Protocols\",\"volume\":\"18 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2009-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2009 5th IEEE Workshop on Secure Network Protocols\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/NPSEC.2009.5342251\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 5th IEEE Workshop on Secure Network Protocols","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NPSEC.2009.5342251","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

研究了混合流中的分组分类问题。给定一个由来自不同来源的不同协议流组成的加密混合流;我们研究是否有可能将数据包分配到各自的源,并确定每个源的协议。加密使得从包头或有效负载中获取任何信息变得困难。因此,观察者唯一能得到的信息是数据包的大小、到达时间、方向和功率水平。本文提出了一种统计方法,分析属于每种协议的数据包的大小和功率级别,并使用这些信息对混合流中的数据包进行分类。结果提出了一个混合流的分类多达五种不同的协议。结果表明,基于大小、方向和功率等级对数据包进行有效分类是可能的。我们看到,属于HTTP协议的数据包最容易分类,而属于FTP和IMAP协议的数据包在相互混合时很难分离。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Packet classification in co-mingled traffic streams
This paper considers the problem of packet classification in a co-mingled traffic stream. Given an encrypted co-mingled stream consisting of different protocol flows originating from different sources; we investigate if it is possible to assign packets to their respective sources and identify the protocol for each source. Encryption makes it difficult to obtain any information from packet headers or payloads. Consequently the only information available to an observer is the packet size, arrival times, direction and power levels. This paper presents a statistical approach that analyses the sizes and power levels of packets belonging to each protocol and uses this information to classify the packets in the co-mingled stream. Results are presented for the classification of a co-mingled stream of upto five different protocols. The results show that it is possible to efficiently classify packets based on sizes, direction and power levels. We see that packets belonging to the HTTP protocol are easiest to classify whereas those belonging to the FTP and IMAP protocols are difficult to separate when co-mingled with each other.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信