• DocumentCode
    3659237
  • Title

    A method for service identification of SSL/TLS encrypted traffic with the relation of session ID and Server IP

  • Author

    Sung-Min Kim;Young-Hoon Goo;Myung-Sup Kim;Soo-Gil Choi;Mi-Jung Choi

  • Author_Institution
    Dept. of Computer and Information Science, Korea University, Korea
  • fYear
    2015
  • Firstpage
    487
  • Lastpage
    490
  • Abstract
    The SSL/TLS, one of the most popular encryption protocol, was developed as a solution of various network security problem while the network traffic has become complex and diverse. But the SSL/TLS traffic has been identified as its protocol name, not its used services, which is required for the effective network traffic management. This paper proposes a new method to generate service signatures automatically from SSL/TLS payload data and to classify network traffic in accordance with their application services. We utilize the certificate publication information field in the certificate exchanging record of SSL/TLS traffic for the service signatures, which occurs when SSL/TLS performs Handshaking before encrypt transmission. We proved the performance and feasibility of the proposed method by experimental result that classify about 95% SSL/TLS traffic with about 90% accuracy for every SSL/TLS services.
  • Keywords
    "Servers","Cryptography","Protocols","IP networks","Payloads","Accuracy","Telecommunication traffic"
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (APNOMS), 2015 17th Asia-Pacific
  • Type

    conf

  • DOI
    10.1109/APNOMS.2015.7275373
  • Filename
    7275373