DocumentCode
3659237
Title
A method for service identification of SSL/TLS encrypted traffic with the relation of session ID and Server IP
Author
Sung-Min Kim;Young-Hoon Goo;Myung-Sup Kim;Soo-Gil Choi;Mi-Jung Choi
Author_Institution
Dept. of Computer and Information Science, Korea University, Korea
fYear
2015
Firstpage
487
Lastpage
490
Abstract
The SSL/TLS, one of the most popular encryption protocol, was developed as a solution of various network security problem while the network traffic has become complex and diverse. But the SSL/TLS traffic has been identified as its protocol name, not its used services, which is required for the effective network traffic management. This paper proposes a new method to generate service signatures automatically from SSL/TLS payload data and to classify network traffic in accordance with their application services. We utilize the certificate publication information field in the certificate exchanging record of SSL/TLS traffic for the service signatures, which occurs when SSL/TLS performs Handshaking before encrypt transmission. We proved the performance and feasibility of the proposed method by experimental result that classify about 95% SSL/TLS traffic with about 90% accuracy for every SSL/TLS services.
Keywords
"Servers","Cryptography","Protocols","IP networks","Payloads","Accuracy","Telecommunication traffic"
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium (APNOMS), 2015 17th Asia-Pacific
Type
conf
DOI
10.1109/APNOMS.2015.7275373
Filename
7275373
Link To Document