DocumentCode
245604
Title
PeerSorter: Classifying Generic P2P Traffic in Real-Time
Author
Jie He ; Yuexiang Yang ; Xiaolei Wang ; Yingzhi Zeng ; Chuan Tang
Author_Institution
Coll. of Comput., Nat. Univ. of Defense Technol., Changsha, China
fYear
2014
fDate
19-21 Dec. 2014
Firstpage
605
Lastpage
613
Abstract
The rapid development of Peer-to-Peer (P2P) technology brings challenges to quality of service (QoS), network planning and access control. An accurate classification of P2P traffic is vital for addressing those challenges. Traditional port-based and payload-based methods fail to cope with emerging port disguise and payload encryption techniques. In this paper, we present Peer Sorter, a system for the classification of generic P2P traffic in real-time. Peer Sorter is featured by four characteristics. Firstly, it can accurately classify nearly all kinds of legitimate P2P applications as well as various P2P botnets, by building application profiles of their significant network activity patterns. Moreover, Peer Sorter is capable of real-time processing, because of its simplicity of mechanism and small classification time windows. In addition, Peer Sorter can be readily extended by adding profiles of new P2P applications. Finally, Peer Sorter can work well even in the scenario where the classification target is running along with other bandwidth consumer (including P2P applications) at the same time. We evaluate the performance of Peer Sorter on traffic datasets of a large variety of P2P applications, including two popular P2P botnets. The experimental results demonstrate that we can classify all the considered types of P2P traffic with an average true positive rate of 97.83% and an average false positive rate below 0.04% within 2 minutes.
Keywords
authorisation; invasive software; pattern classification; peer-to-peer computing; quality of service; P2P botnets; PeerSorter; QoS; access control; generic P2P traffic classification; network planning; peer-to-peer technology; quality of service; Feature extraction; IP networks; Peer-to-peer computing; Ports (Computers); Protocols; Real-time systems; Training; botnet; peer to peer; real-time; traffic classification;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
Conference_Location
Chengdu
Print_ISBN
978-1-4799-7980-6
Type
conf
DOI
10.1109/CSE.2014.134
Filename
7023644
Link To Document