DocumentCode
2926183
Title
Application identification from encrypted traffic based on characteristic changes by encryption
Author
Okada, Yohei ; Ata, Shingo ; Nakamura, Nobuyuki ; Nakahira, Yoshihiro ; Oka, Ikuo
Author_Institution
Grad. Sch. of Eng., Osaka City Univ., Osaka, Japan
fYear
2011
fDate
10-12 May 2011
Firstpage
1
Lastpage
6
Abstract
Application identification is paid much attention by network operators to manage application based traffic control in the Internet. However, encryption is one of the factors to make application identification difficult, because it is so hard to infer the original (unencrypted) packets from encrypted packets. Therefore the accuracy of application identification is getting worse as the increase of encrypted traffic. In this paper, the changes in traffic features due to encryption are analyzed, and two methods are developed that can be used with an existing method for identifying applications from encrypted traffic. Experimental results show that these methods improve identification accuracy up to 28.5% for encrypted traffic compared to existing methods. Moreover, identification using the best combination of flow features enables high accuracy with less computation due to the elimination of features that do not flow a Gaussian distribution and thus degrade accuracy.
Keywords
Gaussian distribution; Internet; computer network security; cryptography; Gaussian distribution; Internet; application identification; network operators; traffic control; traffic encryption; Accuracy; Correlation; Encryption; Monitoring; Servers; Training data;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications Quality and Reliability (CQR), 2011 IEEE International Workshop Technical Committee on
Conference_Location
Naples, FL
Print_ISBN
978-1-4577-1297-5
Electronic_ISBN
978-1-4577-1296-8
Type
conf
DOI
10.1109/CQR.2011.5996087
Filename
5996087
Link To Document