• DocumentCode
    124406
  • Title

    Towards real-time processing for application identification of encrypted traffic

  • Author

    Kumano, Yuichi ; Ata, Shingo ; Nakamura, N. ; Nakahira, Yoshihiro ; Oka, Ikuo

  • Author_Institution
    Grad. Sch. of Eng., Osaka City Univ., Osaka, Japan
  • fYear
    2014
  • fDate
    3-6 Feb. 2014
  • Firstpage
    136
  • Lastpage
    140
  • Abstract
    Application identification in the middle is one of key challenges for network operators to manage application based traffic and policy controls in the Internet. However, it is becoming harder according to the increase of end-to-end encrypted traffic in which we hardly read application specific information from packets. We previously proposed a method to identify the application of traffic whenever the traffic is encrypted or not. Our method gives a significant accuracy of identification of encrypted traffic as high as the case when traffic is not encrypted, however, it requires an offline processing to obtain statistics of the whole of flows. A real-time identification is important, but the accuracy is a problem due to unstable information of flow statistics. In this paper we therefore propose an approach to improve the accuracy of identification when we identify the encrypted traffic in real-time. We first clarify the sufficient number of packets required for accurate identification, and then the method to infer the statistics to improve the accuracy even when the obtained number of packets is smaller than the one required. Experimental results have shown that the proposed approach achieves the high accuracy almost the same as in offline method.
  • Keywords
    Internet; computer network security; cryptography; identification; telecommunication traffic; Internet; application based traffic; application specific information; encrypted traffic identification; end-to-end encrypted traffic; flow statistics; offline processing; policy controls; real-time processing; Accuracy; Degradation; Encryption; Monitoring; Real-time systems; Training data;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing, Networking and Communications (ICNC), 2014 International Conference on
  • Conference_Location
    Honolulu, HI
  • Type

    conf

  • DOI
    10.1109/ICCNC.2014.6785319
  • Filename
    6785319