A first look at traffic classification in enterprise networks

A first look at traffic classification in enterprise networks
复制标题

企业网络中的流量分类初探

DOI:
10.1145/1815396.1815571
复制
发表时间:
2010
影响因子:
1.5
通讯作者:
G. Urvoy
G. Urvoy
中科院分区:
计算机科学4区
文献类型:
--
作者:
T. En;G. Urvoy

文献摘要

被引文献

相似文献

企业网络的复杂性有时可以与大型互联网相媲美。尽管如此,到目前为止,企业流量几乎没有受到研究界的关注。大多数研究依赖于端口号来识别应用程序。 在这项工作中,我们介绍了一种方法来建立统计分类检测特定的内部网应用程序。 我们用Eurecom网络内收集的痕迹来验证这种方法。我们证明了我们的统计分类器能够对我们的轨迹中的大多数流量进行分类。对于特定端口上的流量无法完全由我们的应用程序/协议解码器识别的情况,例如,加密流量,我们证明,我们的方法可以用来测试交通的同质性,即,相应的流共享与其余业务之一不同的公共统计签名。
Enterprise networks have a complexity that sometimes rival the one of the larger Internet. Still, enterprise traffic has received little attention so far from the research community. Most studies rely on port numbers to identify applications. In this work, we introduce a method to build statistical classifiers to detect specific intranet applications. We exemplify the approach with traces collected within the Eurecom network. We demonstrate that our statistical classifiers are able to classify the majority of the flows in our traces. For the cases when the traffic on a specific port cannot be fully identified with our application/protocol decoder, e.g., encrypted traffic, we demonstrate that our approach can be used to test the homogeneity of the traffic, i.e., that the corresponding flows share a common statistical signature that differs from the one of the rest of the traffic.