• DocumentCode
    1575033
  • Title

    DRPSD: An novel method of identifying SSL/TLS traffic

  • Author

    Changxing Liu ; Guanglu Sun ; Yibo Xue

  • Author_Institution
    School of Computer, Harbin University of Science and Technology, China
  • fYear
    2012
  • Firstpage
    415
  • Lastpage
    419
  • Abstract
    More and more Internet applications transmit data with encrypted protocols, so how to identify network traffic which use encrypted protocols is very important to network control and management. However, traditional traffic identification methods, such as port-based, payload-based and statistic-based methods are invalid or inaccurate for most of encrypted protocols. In this paper, we propose a new method (called DRPSD) to identify encrypted traffic which uses SSL/TLS protocol. In DRPSD, we only check the first few packets in a connection, and double record protocol structure is detected in each packet, instead of checking each byte in the packet. The experimental results show that, our method can improve accuracy rate by 20% and identifying speed by 200% in identifying SSL protocol compared with the open source software OpenDPI.
  • Keywords
    DRPSD; Encrypted traffic; SSL/TLS protocol; Structure-based;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    World Automation Congress (WAC), 2012
  • Conference_Location
    Puerto Vallarta, Mexico
  • ISSN
    2154-4824
  • Print_ISBN
    978-1-4673-4497-5
  • Type

    conf

  • Filename
    6321091