• DocumentCode
    2220912
  • Title

    SANTaClass: A Self Adaptive Network Traffic Classification system

  • Author

    Tongaonkar, Alok ; Keralapura, Ram ; Nucci, Antonio

  • Author_Institution
    Narus Inc., USA
  • fYear
    2013
  • fDate
    22-24 May 2013
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    A critical aspect of network management from an operator´s perspective is the ability to understand or classify all traffic that traverses the network. The failure of port based traffic classification technique triggered an interest in discovering signatures based on packet content. However, this approach involves manually reverse engineering all the applications/protocols that need to be identified. This suffers from the problem of scalability; keeping up with the new applications that come up everyday is very challenging and time-consuming. Moreover, traditional approach of developing signatures once and using them in different networks suffers from low coverage. In this work, we present a novel fully automated packet payload content (PPC) based network traffic classification system that addresses the above shortcomings. Our system learns new application signatures in the network where classification is desired. Further more, our system adapts the signatures as the traffic for an application changes. Based on real traces from several service providers, we show that our system is capable of detecting (1) tunneled or wrapped applications, (2) applications that use random ports, and (3) new applications. Moreover, it is robust to routing asymmetry, an important requirement in large ISPs, and has a very high (>99.5%) detection rate. Finally, our system is easy to deploy and setup and performs classification in real-time.
  • Keywords
    Internet; computer network management; reverse engineering; telecommunication network routing; telecommunication traffic; ISP; Internet service providers; PPC; SANTaClass; network management; packet content; packet payload content; port based traffic classification; reverse engineering; routing asymmetry; self adaptive network traffic classification system; signature generator; Cryptography; Databases; Payloads; Protocols; Real-time systems; Reverse engineering; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IFIP Networking Conference, 2013
  • Conference_Location
    Brooklyn, NY
  • Type

    conf

  • Filename
    6663505