Can we trust the inter-packet time for traffic classification?

Autor: Roberto G. Cascella, Mohamad Y. Jaber, Chadi Barakat
Přispěvatelé: Protocols and applications for the Internet (PLANETE), Inria Grenoble - Rhône-Alpes, Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria)-Inria Sophia Antipolis - Méditerranée (CRISAM), Institut National de Recherche en Informatique et en Automatique (Inria), ANR CMON project on Collaborative Monitoring,ANR CMON project on Collaborative Monitoring, ANR-08-VERS-0004,CMON,Métrologie Collaborative(2008)
Jazyk: angličtina
Rok vydání: 2011
Předmět:
Zdroj: IEEE International Conference on Communications (ICC)
[Research Report] 2011
ICC
Popis: International audience; The identification of Internet applications is important for ISPs and network administrators to protect the network from unwanted traffic and prioritize some major applications. Statistical methods are widely used since they allow to classify applications according to their statistical signatures. They combine the statistical analysis of flow parameters, such as packet size and inter-packet time, with machine learning techniques. Previous works are mainly based on the packet size and the directions of the packets. In this work we make a complete study about the interpacket time to prove that it is also a valuable information for the classification of Internet traffic. We discuss how to isolate the noise due to the network conditions and extract the time generated by the application. We present a model to preprocess the inter-packet time and use the result as input to the learning process. We discuss an iterative approach for the on line identification of the applications and we evaluate our method on two different real traces. The results show that the inter-packet time is an important parameter to classify Internet traffic.
Databáze: OpenAIRE