loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
2010 24th IEEE International Conference on Advanced Information Networking and Applications
Automatic Application Signature Construction from Unknown Traffic
Perth, Australia
April 20-April 23
ISBN: 978-0-7695-4018-4
Identifying applications and classifying network traffic flows according to their source applications are critical for a broad range of network activities. Such classifications can be based on information derived from packet header fields and payload content, or statistical characteristics of flows and communication patterns of hosts. However, most of present methods rely on some forms of priori knowledge. In this paper, an application signature based traffic classification system with a novel approach to fully automate the process of deriving signatures from unknown traffic is proposed. The key idea is to combine traffic clustering based on statistical flow properties in order to generate clusters dominated by a single application on the one hand, and application signature construction solely based on payload content from each cluster on the other hand. Evaluation using real-world traffic traces indicate that the proposed approach is highly effective.
Index Terms:
traffic classification, application identification, machine learning, clustering
Citation:
Yu Wang, Yang Xiang, Shun-Zheng Yu, "Automatic Application Signature Construction from Unknown Traffic," aina, pp.1115-1120, 2010 24th IEEE International Conference on Advanced Information Networking and Applications, 2010
Usage of this product signifies your acceptance of the Terms of Use.