DocumentCode
2205037
Title
Comparison and Analysis of Flow Features at the Packet Level for Traffic Classification
Author
Gang Lu ; Hongli Zhang ; Qassrawi, M. ; Xiangzhan Yu
Author_Institution
Sch. of Comput. Sci. & Technol., Harbin Inst. of Technol., Harbin, China
fYear
2012
fDate
12-16 Dec. 2012
Firstpage
262
Lastpage
267
Abstract
Recently, flow features at the packet level for traffic classification have been paid more attention to since they are simple and observable even if encrypted tunnels are applied in the network, such as SSL tunnel. However, how to use flow features at the packet level for effective classification of traffic flows is still a significant issue to be solved. The objective of this paper is to compare and analyze three typical flow features at the packet level: packet size combined with packet direction, packet size combined with interarrival time, and protocol fingerprint. The amount of information carried by each feature is presented with mutual information measurement. Based on the traffic traces captured from two different network environments, our experimental results indicate that when C4.5 algorithm classifies traffic flows with the first two packets of each flow, packet size combined with packet interarrival time, which is generated from the client-to-server direction of a TCP connection, is more accurate and stable across space and time.
Keywords
client-server systems; cryptography; telecommunication security; telecommunication traffic; transport protocols; C4.5 algorithm; SSL tunnel; TCP connection; client-to-server direction; flow feature; mutual information measurement; packet level; protocol fingerprint; traffic classification; traffic flow classification; tunnel encryption; flow features; packet level; traffic classification;
fLanguage
English
Publisher
ieee
Conference_Titel
Connected Vehicles and Expo (ICCVE), 2012 International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4673-4705-1
Type
conf
DOI
10.1109/ICCVE.2012.58
Filename
6519583
Link To Document