Title
A statistical approach to IP-level classification of network traffic
Abstract
Correct classification of traffic flows according to the application layer protocols that generated them is essential for most network-management, resource allocation and intrusion detection systems in TCP/IP networks. With the ever increasing number of network protocols and services running on non- standard TCP ports, the classification methods based on the analysis of the transport layer header are rapidly becoming ineffective. On the other hand, mechanisms based on full payload analysis are too computationally demanding to be run on most high-bandwidth links. Here we present a novel classification technique based on the statistical analysis of network traffic performed at the IP-level. The key idea behind our approach is to build a set of protocol fingerprints that we believe summarize, in a compact and efficient way, the main IP-level statistical properties of application layer protocols. By means of a simple, lightweight algorithm based on the notion of anomaly scores, also presented in this paper, an unknown flow can be compared against known protocol fingerprints, detecting the application that generated the flow. Our methodology is completely based on IP-level analysis: no payload analysis or port analysis is required for the classification of an unknown flow. Besides introducing our approach, we describe preliminary experimental results that show how this technique is effective in correctly classifying network traffic in a real network environment.
Year
DOI
Venue
2006
10.1109/ICC.2006.254723
Communications, 2006. ICC '06. IEEE International Conference
Keywords
Field
DocType
Traffic classification,traffic measurement
Traffic classification,Application layer,Computer science,Computer network,Internet protocol suite,Transport layer,Header,Intrusion detection system,Distributed computing,Payload,Communications protocol
Conference
Volume
ISSN
ISBN
1
8164-9547 E-ISBN : 1-4244-0355-3
1-4244-0355-3
Citations 
PageRank 
References 
23
1.18
12
Authors
4
Name
Order
Citations
PageRank
Manuel Crotti124612.62
Francesco Gringoli289061.65
Paolo Pelosato3231.18
Luca Salgarelli493781.17