Protocol Identification of Encrypted Network Traffic

Protocol Identification of Encrypted Network Traffic
复制标题

加密网络流量的协议识别

DOI:
10.1109/wi.2006.139
复制
发表时间:
2006
期刊:
2006 IEEE/WIC/ACM International Conference on Web Intelligence (WI 2006 Main Conference Proceedings)(WI'06)
影响因子:
--
通讯作者:
R. Wong
R. Wong
中科院分区:
--
文献类型:
--
作者:
M. Gebski;A. Penev;R. Wong

文献摘要

被引文献

相似文献

新的通信手段不断涌现,其中一些可能构成对组织网络系统资源的滥用。在检查网络日志时,识别所使用的协议是直截了当的,但我们关注的问题是识别未知TCP连接中存在的底层协议。如果底层协议通过代理服务器或SSH进行了加密和隧道化,则很难检测操作。我们使用图形比较方法来构建几个协议的配置文件,并尝试根据这些配置文件对未知的加密协议进行分类,仅使用正在隧道传输的协议的可见行为-数据包的大小,时间和方向
New means of communication are constantly emerging, some of which may constitute resource misuse of an organisation's network system. Identifying the protocols used is straight-forward when inspecting network logs, but we focus on the problem of identifying the underlying protocol present in an unknown TCP connection. Actions are difficult to detect if the underlying protocol is encrypted and tunneled through a proxy server or SSH. We use a graph-comparison approach to build profiles of several protocols, and attempt to classify an unknown, encrypted protocol against these profiles using only the visible behaviour of the protocol being tunneled - the size, timing and direction of packets