DocumentCode :
690477
Title :
Performance of OpenDPI to identify truncated network traffic
Author :
Khalife, Jawad ; Hajjar, Amjad ; Diaz-Verdejo, Jesus
Author_Institution :
Faculty of Engineering, IT Department, Lebanese University, Beirut, Lebanon
fYear :
2011
fDate :
18-21 July 2011
Firstpage :
1
Lastpage :
6
Abstract :
The identification of the nature of the traffic flowing through a TCP/IP network is a relevant target for traffic engineering and security related tasks. Traditional methods based on port assignments are no longer valid due to the use of ephemeral ports and ciphering. Despite the privacy concerns it arises, Deep Packet Inspection (DPI) is one of the most successful current techniques. Nevertheless, the performance of DPI is strongly limited by computational issues related to the huge amount of data it needs to handle, both in terms of number of packets and the length of the packets. This paper addresses the sensitivity of OpenDPI, one of the most powerful freely available DPI systems, when truncation of the payloads of the monitored traffic is applied. The results show that it is highly dependent on the protocol being monitored.
Keywords :
Accuracy; Databases; Inspection; Optimization; Payloads; Ports (Computers); Protocols; Deep packet inspection; Network traffic identification; Payload truncation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Communication Networking (DCNET), 2011 Proceedings of the International Conference on
Conference_Location :
Seville, Spain
Type :
conf
Filename :
6835777
Link To Document :
بازگشت