DocumentCode :
3648361
Title :
Network management without payload inspection: Application classification via statistical analysis of bulk flow data
Author :
Bariş Kurt;A. Taylan Cemgil;Muhittin Mungan;Neval Polat;Alper Özdoğan;Ece Saygun
Author_Institution :
Department of Computer Engineering, Boğ
fYear :
2012
fDate :
7/1/2012 12:00:00 AM
Firstpage :
1
Lastpage :
8
Abstract :
We describe a statistical approach to application classification from network traffic flows. The packet payloads are not investigated, instead we just derive easy to collect statistics such as packet size, download/upload direction, protocol and interarrival time, along with ip-number:port pairs. Each flow is modeled by a mixture of Markov models. We employ a nonparametric Bayesian approach to identify flow clusters. An important feature of our clustering method is that we don´t have to specify the number of clusters in advance and the model is able to infer new flow types in an unsupervised manner. We illustrate our approach on a real dataset collected from live traffic.
Keywords :
"Feature extraction","Inspection","Bayesian methods","Payloads","Protocols","IP networks","Markov processes"
Publisher :
ieee
Conference_Titel :
Future Network & Mobile Summit (FutureNetw), 2012
Print_ISBN :
978-1-4673-0320-0
Type :
conf
Filename :
6294231
Link To Document :
بازگشت