Semi-automated discovery of application session structure

Semi-automated discovery of application session structure
复制标题

DOI:
10.1145/1177080.1177096
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
Jayanthkumar Kannan;Jaeyeon Jung;V. Paxson;C. E. Koksal
Jayanthkumar Kannan;Jaeyeon Jung;V. Paxson;C. E. Koksal
中科院分区:
其他
文献类型:
--
作者:
Jayanthkumar Kannan;Jaeyeon Jung;V. Paxson;C. E. Koksal

文献摘要

被引文献

相似文献

虽然以前已经进行了大量的工作和工具开发,但在更高级别(由相关连接组组成的用户发起的会话的结构)上理解流量的问题仍然很少探索。某些类型的会话结构,例如FTP控制连接和它产生的数据连接之间的耦合,具有预先指定的形式,尽管规范不保证这些形式在实践中如何出现。其他类型的会话,例如用户使用浏览器阅读电子邮件,仅凭经验表现。还有一些会话可能在我们甚至不知道它们的存在的情况下存在,例如僵尸网络僵尸从其主人那里接收指令并依次执行它们。我们提出的算法植根于统计的泊松过程,可以挖掘一个大型语料库的网络连接日志中提取的连接中嵌入的应用程序会话的表观结构。我们的方法是半自动化的,我们的目标是向分析师提供高质量的信息(表示为正则表达式),反映应用程序的会话结构的不同可能的抽象。我们开发和测试我们的方法使用的痕迹,从一个大型的互联网网站,发现多样性的应用程序的数量,表现出不同的会话结构,以及存在异常行为。我们的工作有应用程序的流量表征和监测,源模型合成网络流量,和异常检测。
While the problem of analyzing network traffic at the granularity of individual connections has seen considerable previous work and tool development, understanding traffic at a higher level - the structure of user-initiated sessions comprised of groups of related connections - remains much less explored. Some types of session structure, such as the coupling between an FTP control connection and the data connections it spawns, have prespecified forms, though the specifications do not guarantee how the forms appear in practice. Other types of sessions, such as a user reading email with a browser, only manifest empirically. Still other sessions might exist without us even knowing of their presence, such as a botnet zombie receiving instructions from its master and proceeding in turn to carry them out. We present algorithms rooted in the statistics of Poisson processes that can mine a large corpus of network connection logs to extract the apparent structure of application sessions embedded in the connections. Our methods are semi-automated in that we aim to present an analyst with high-quality information (expressed as regular expressions) reflecting different possible abstractions of an application's session structure. We develop and test our methods using traces from a large Internet site, finding diversity in the number of applications that manifest, their different session structures, and the presence of abnormal behavior. Our work has applications to traffic characterization and monitoring, source models for synthesizing network traffic, and anomaly detection.