Unexpected means of protocol inference

Unexpected means of protocol inference
复制标题

DOI:
10.1145/1177080.1177123
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
Justin Ma;Kirill Levchenko;C. Kreibich;S. Savage;G. Voelker
Justin Ma;Kirill Levchenko;C. Kreibich;S. Savage;G. Voelker
中科院分区:
其他
文献类型:
--
作者:
Justin Ma;Kirill Levchenko;C. Kreibich;S. Savage;G. Voelker

文献摘要

被引文献

相似文献

网络管理人员不可避免地需要将网络流量与特定应用程序相关联。事实上,此操作对于从调试和安全到分析和策略支持的各种管理功能都至关重要。传统上,管理人员依赖于应用程序遵守一个完善的全局端口映射:端口80上的Web流量,端口25上的邮件流量等。但是,一系列因素-包括防火墙端口阻塞,隧道,动态端口分配和新的分布式应用程序的激增-削弱了这种方法的价值。我们分析了三种替代机制,使用统计和结构化的内容模型自动识别流量,使用相同的应用层协议,只依赖于流的内容。以这种方式,可以识别已知应用而不管端口号,而来自一个未知应用的业务将被识别为与另一个不同。我们评估每个机制的分类性能,使用现实世界中的交通痕迹,从多个网站。
Network managers are inevitably called upon to associate network traffic with particular applications. Indeed, this operation is critical for a wide range of management functions ranging from debugging and security to analytics and policy support. Traditionally, managers have relied on application adherence to a well established global port mapping: Web traffic on port 80, mail traffic on port 25 and so on. However, a range of factors - including firewall port blocking, tunneling, dynamic port allocation, and a bloom of new distributed applications - has weakened the value of this approach. We analyze three alternative mechanisms using statistical and structural content models for automatically identifying traffic that uses the same application-layer protocol, relying solely on flow content. In this manner, known applications may be identified regardless of port number, while traffic from one unknown application will be identified as distinct from another. We evaluate each mechanism's classification performance using real-world traffic traces from multiple sites.