ACAS: automated construction of application signatures

ACAS: automated construction of application signatures
复制标题

DOI:
10.1145/1080173.1080183
复制
发表时间:
2005-08
期刊:
--
影响因子:
--
通讯作者:
P. Haffner;S. Sen;Oliver Spatscheck;Dongmei Wang
P. Haffner;S. Sen;Oliver Spatscheck;Dongmei Wang
中科院分区:
其他
文献类型:
--
作者:
P. Haffner;S. Sen;Oliver Spatscheck;Dongmei Wang

文献摘要

被引文献

相似文献

流量到应用程序的准确映射对于广泛的网络管理和测量任务非常重要。传统上,互联网应用程序是使用TCP或UDP报头中众所周知的默认服务器网络端口号来标识的。然而,这种方法变得越来越不准确。另一种更精确的技术是在协议交换中使用特定的应用程序级特性来指导识别。在本文中,我们探讨了从IP流量的有效载荷内容中自动提取应用程序签名的方法。特别是,我们应用三种统计机器学习算法来自动识别一系列应用的签名。结果表明,这种方法是高度准确的和规模,以允许在高速链路上的在线应用程序识别。我们还发现,内容签名在存在加密的情况下仍然有效。在这些情况下,我们能够推导出未加密握手的内容签名,协商特定连接的加密参数。
An accurate mapping of traffic to applications is important for a broad range of network management and measurement tasks. Internet applications have traditionally been identified using well-known default server network-port numbers in the TCP or UDP headers. However this approach has become increasingly inaccurate. An alternate, more accurate technique is to use specific application-level features in the protocol exchange to guide the identification. Unfortunately deriving the signatures manually is very time consuming and difficult.In this paper, we explore automatically extracting application signatures from IP traffic payload content. In particular we apply three statistical machine learning algorithms to automatically identify signatures for a range of applications. The results indicate that this approach is highly accurate and scales to allow online application identification on high speed links. We also discovered that content signatures still work in the presence of encryption. In these cases we were able to derive content signature for unencrypted handshakes negotiating the encryption parameters of a particular connection.