A first look at traffic classification in enterprise networks
A first look at traffic classification in enterprise networks
复制标题
企业网络中的流量分类初探
DOI:
10.1145/1815396.1815571
复制
发表时间:
2010
影响因子:
1.5
通讯作者:
G. Urvoy
中科院分区:
文献类型:
--
作者:
T. En;G. Urvoy
Enterprise networks have a complexity that sometimes rival the one of the larger Internet. Still, enterprise traffic has received little attention so far from the research community. Most studies rely on port numbers to identify applications.
In this work, we introduce a method to build statistical classifiers to detect specific intranet applications.
We exemplify the approach with traces collected within the Eurecom network. We demonstrate that our statistical classifiers are able to classify the majority of the flows in our traces. For the cases when the traffic on a specific port cannot be fully identified with our application/protocol decoder, e.g., encrypted traffic, we demonstrate that our approach can be used to test the homogeneity of the traffic, i.e., that the corresponding flows share a common statistical signature that differs from the one of the rest of the traffic.