Title :
Signature management system to cope with traffic changes in application and service
Author :
Kyu-Seok Shim;Sung-Ho Yoon;Mi-Jung Choi;Myung-Sup Kim
Author_Institution :
Dept. of Computer and Information Science, Korea University, Sejong, Korea
Abstract :
Today, the number of applications using network service has been increasing. Also, many applications have changed their traffic pattern frequently due to various reasons. Nevertheless, network managers tend to stay with old signatures. But they should update with new signatures to detect the modified application traffic. The extraction of signature is work to demand a lot of time. And it is difficult to continuously and timely extract the new signature for all applications. In this paper, we propose a noble signature management system which automatically extract new signatures detecting the modified traffic and delete old signatures no longer used. The proposed system analyzes traffic with existing signatures and extracts new signature automatically for updated traffic. For automatic generation of new signatures, we uses a sequence pattern algorithm. Also, the proposed system analyze usage of the old signatures to remove them when they are not used any more. We proved the feasibility and applicability of the proposed system by showing that that detection rate of all application was increased.
Keywords :
"Payloads","Ports (Computers)","Cryptography","YouTube","IP networks","Protocols","Facebook"
Conference_Titel :
Network Operations and Management Symposium (APNOMS), 2015 17th Asia-Pacific
DOI :
10.1109/APNOMS.2015.7275425