Classifying Network Protocols: A ‘2 Way’ Flow Approach


Autoria(s): Hurley, Richard; Garcia-Palacios, Emi; Sezer, Sakir
Data(s)

04/01/2011

Resumo

The identification and classification of network traffic and protocols is a vital step in many quality of service and security systems. Traffic classification strategies must evolve, alongside the protocols utilising the Internet, to overcome the use of ephemeral or masquerading port numbers and transport layer encryption. This research expands the concept of using machine learning on the initial statistics of flow of packets to determine its underlying protocol. Recognising the need for efficient training/retraining of a classifier and the requirement for fast classification, the authors investigate a new application of k-means clustering referred to as 'two-way' classification. The 'two-way' classification uniquely analyses a bidirectional flow as two unidirectional flows and is shown, through experiments on real network traffic, to improve classification accuracy by as much as 18% when measured against similar proposals. It achieves this accuracy while generating fewer clusters, that is, fewer comparisons are needed to classify a flow. A 'two-way' classification offers a new way to improve accuracy and efficiency of machine learning statistical classifiers while still maintaining the fast training times associated with the k-means.

Formato

application/pdf

Identificador

http://pure.qub.ac.uk/portal/en/publications/classifying-network-protocols-a-2-way-flow-approach(b4e42fc3-0628-4e79-b5b6-bf9787430cba).html

http://dx.doi.org/10.1049/iet-com.2009.0776

http://pure.qub.ac.uk/ws/files/644250/HurleyIETComms05672995.pdf

http://www.scopus.com/inward/record.url?scp=78650293585&partnerID=8YFLogxK

Idioma(s)

eng

Direitos

info:eu-repo/semantics/restrictedAccess

Fonte

Hurley , R , Garcia-Palacios , E & Sezer , S 2011 , ' Classifying Network Protocols: A ‘2 Way’ Flow Approach ' IET Communications , vol 5 , no. 1 , pp. 79-89 . DOI: 10.1049/iet-com.2009.0776

Palavras-Chave #/dk/atira/pure/subjectarea/asjc/2200/2208 #Electrical and Electronic Engineering #/dk/atira/pure/subjectarea/asjc/1700/1706 #Computer Science Applications
Tipo

article