DocumentCode :
2906301
Title :
Stochastic Packet Inspection for TCP Traffic
Author :
La Mantia, Gianluca ; Rossi, Dario ; Finamore, Alessandro ; Mellia, Marco ; Meo, Michela
Author_Institution :
INFRES Dept., TELECOM ParisTech, Paris, France
fYear :
2010
fDate :
23-27 May 2010
Firstpage :
1
Lastpage :
6
Abstract :
In this paper, we extend the concept of Stochastic Packet Inspection (SPI) to support TCP traffic classification. SPI is a method based on the statistical fingerprint of the application-layer headers: by characterizing the frequencies of observed symbols, SPI can identify application protocol formats by automatically recognizing group of bits that take e.g., constant values, or random values, or are part of a counter. To correctly characterize symbol frequencies, SPI needs volumes of traffic to obtain statistically significant signatures. Earlier proposed for UDP traffic, SPI has to be modified to cope with the connection oriented service offered by TCP, in which application-layer headers are only found at the beginning of a TCP connection. In this paper, we extend SPI to support TCP traffic, and analyze its performance on real network data. The key idea is to move the classification target from single flows to endpoints, which aggregates all traffic sent/received by the same IP address and TCP port pair. The first few packets of flows sent from (or destined to) the same endpoint are then aggregated to yield a single SPI signature. Results show that SPI is able to achieve remarkably good results, with an average true positive rate of about 98%.
Keywords :
statistical analysis; stochastic processes; transport protocols; TCP traffic classification; application-layer header; statistical fingerprint; stochastic packet inspection; symbol frequencies; Character recognition; Counting circuits; Fingerprint recognition; Frequency; Inspection; Performance analysis; Protocols; Stochastic processes; TCPIP; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications (ICC), 2010 IEEE International Conference on
Conference_Location :
Cape Town
ISSN :
1550-3607
Print_ISBN :
978-1-4244-6402-9
Type :
conf
DOI :
10.1109/ICC.2010.5502280
Filename :
5502280
Link To Document :
بازگشت