• DocumentCode
    2835795
  • Title

    A statistical approach to IP-level classification of network traffic

  • Author

    Crotti, Manuel ; Gringoli, Francesco ; Pelosato, Paolo ; Salgarelli, Luca

  • Author_Institution
    DEA, Universitá degli Studi di Brescia, via Branze, 38, 25123 Brescia, Italy. E-mail: Manuel.Crotti@ing.unibs.it
  • Volume
    1
  • fYear
    2006
  • fDate
    38869
  • Firstpage
    170
  • Lastpage
    176
  • Abstract
    Correct classification of traffic flows according to the application layer protocols that generated them is essential for most network-management, resource allocation and intrusion detection systems in TCP/IP networks. With the ever increasing number of network protocols and services running on non-standard TCP ports, the classification methods based on the analysis of the transport layer header are rapidly becoming ineffective. On the other hand, mechanisms based on full payload analysis are too computationally demanding to be run on most high-bandwidth links. Here we present a novel classification technique based on the statistical analysis of network traffic performed at the IP-level. The key idea behind our approach is to build a set of protocol fingerprints that we believe summarize, in a compact and efficient way, the main IP-level statistical properties of application layer protocols. By means of a simple, lightweight algorithm based on the notion of anomaly scores, also presented in this paper, an unknown flow can be compared against known protocol fingerprints, detecting the application that generated the flow. Our methodology is completely based on IP-level analysis: no payload analysis or port analysis is required for the classification of an unknown flow. Besides introducing our approach, we describe preliminary experimental results that show how this technique is effective in correctly classifying network traffic in a real network environment.
  • Keywords
    Communication system traffic control; Fingerprint recognition; IP networks; Intrusion detection; Payloads; Peer to peer computing; Protocols; Resource management; TCPIP; Telecommunication traffic; Traffic classification; traffic measurement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2006. ICC '06. IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    8164-9547
  • Print_ISBN
    1-4244-0355-3
  • Electronic_ISBN
    8164-9547
  • Type

    conf

  • DOI
    10.1109/ICC.2006.254723
  • Filename
    4024113