• DocumentCode
    780069
  • Title

    Using packet size distributions to identify real-time networked applications

  • Author

    Parish, D.J. ; Bharadia, K. ; Larkum, A. ; Phillips, I.W. ; Oliver, M.A.

  • Author_Institution
    Dept. of Electron. & Electr. Eng., Loughborough Univ., UK
  • Volume
    150
  • Issue
    4
  • fYear
    2003
  • Firstpage
    221
  • Lastpage
    227
  • Abstract
    Communication networks, including the Internet, support a wide range of packet-based applications. It is often necessary to know what applications are in use. Traditionally, applications were readily identified by inspection of data held in the packet header such as the destination port number. However, newer and real-time applications cannot always be detected by such a simple investigation and hence other techniques such as packet classification or deep packet analysis have been developed. Deep packet analysis however has significant problems such as its inability to operate on encrypted data packets, and its need to capture specific packets from the traffic stream. The paper considers an alternative approach to the detection of real-time applications. A search was made for a statistical fingerprint derivable from the observable traffic streams generated by such applications. This has been found to be the packet size distribution of the application, and the paper considers this statistic for a range of such applications and network conditions. A detector, based on the described approach, is presented and evaluated using real network traffic.
  • Keywords
    Internet; packet switching; real-time systems; signal detection; statistical analysis; telecommunication traffic; transport protocols; Internet; communication networks; deep packet analysis; destination port number; encryption; network conditions; packet classification; packet header; packet size distribution; packet-based applications; real network traffic; real-time applications; real-time applications detection; real-time networked applications; statistical fingerprint; traffic stream;
  • fLanguage
    English
  • Journal_Title
    Communications, IEE Proceedings-
  • Publisher
    iet
  • ISSN
    1350-2425
  • Type

    jour

  • DOI
    10.1049/ip-com:20030411
  • Filename
    1231275