Title :
PeerSorter: Classifying Generic P2P Traffic in Real-Time
Author :
Jie He ; Yuexiang Yang ; Xiaolei Wang ; Yingzhi Zeng ; Chuan Tang
Author_Institution :
Coll. of Comput., Nat. Univ. of Defense Technol., Changsha, China
Abstract :
The rapid development of Peer-to-Peer (P2P) technology brings challenges to quality of service (QoS), network planning and access control. An accurate classification of P2P traffic is vital for addressing those challenges. Traditional port-based and payload-based methods fail to cope with emerging port disguise and payload encryption techniques. In this paper, we present Peer Sorter, a system for the classification of generic P2P traffic in real-time. Peer Sorter is featured by four characteristics. Firstly, it can accurately classify nearly all kinds of legitimate P2P applications as well as various P2P botnets, by building application profiles of their significant network activity patterns. Moreover, Peer Sorter is capable of real-time processing, because of its simplicity of mechanism and small classification time windows. In addition, Peer Sorter can be readily extended by adding profiles of new P2P applications. Finally, Peer Sorter can work well even in the scenario where the classification target is running along with other bandwidth consumer (including P2P applications) at the same time. We evaluate the performance of Peer Sorter on traffic datasets of a large variety of P2P applications, including two popular P2P botnets. The experimental results demonstrate that we can classify all the considered types of P2P traffic with an average true positive rate of 97.83% and an average false positive rate below 0.04% within 2 minutes.
Keywords :
authorisation; invasive software; pattern classification; peer-to-peer computing; quality of service; P2P botnets; PeerSorter; QoS; access control; generic P2P traffic classification; network planning; peer-to-peer technology; quality of service; Feature extraction; IP networks; Peer-to-peer computing; Ports (Computers); Protocols; Real-time systems; Training; botnet; peer to peer; real-time; traffic classification;
Conference_Titel :
Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4799-7980-6
DOI :
10.1109/CSE.2014.134