Identifying online traffic based on property of TCP flow
Autor: | Hong-xiang Wang, Ren-tao Gu, Min-huo Hong, Yong-mei Sun, Yue-feng Ji |
---|---|
Rok vydání: | 2009 |
Předmět: |
Computer Networks and Communications
Transmission Control Protocol Network packet Computer science business.industry ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS TCP tuning Encryption Network traffic control Computer Science::Performance Naive Bayes classifier Traffic classification Signal Processing Computer Science::Networking and Internet Architecture Traffic shaping business Information Systems Computer network |
Zdroj: | The Journal of China Universities of Posts and Telecommunications. 16:84-88 |
ISSN: | 1005-8885 |
DOI: | 10.1016/s1005-8885(08)60231-9 |
Popis: | Classification of network traffic using port-based or payload-based analysis is becoming increasingly difficult when many applications use dynamic port numbers, masquerading techniques, and encryption to avoid detection. In this article, an approach is presented for online traffic classification relying on the observation of the first n packets of a transmission control protocol (TCP) connection. Its key idea is to utilize the properties of the observed first ten packets of a TCP connection and Bayesian network method to build a classifier. This classifier can classify TCP flows dynamically as packets pass through it by deciding whether a TCP flow belongs to a given application. The experimental results show that the proposed approach performs well in online Internet traffic classification and that it is superior to naive Bayesian method. |
Databáze: | OpenAIRE |
Externí odkaz: |