Certificate-aware encrypted traffic classification using Second-Order Markov Chain

Meng Shen, Mingwei Wei, Liehuang Zhu*, Mingzhong Wang, Fuliang Li

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

46 引用 (Scopus)

摘要

With the prosperity of network applications, traffic classification serves as a crucial role in network management and malicious attack detection. The widely used encryption transmission protocols, such as the Secure Socket Layer/Transport Layer Security (SSL/TLS) protocols, leads to the failure of traditional payload-based classification methods. Existing methods for encrypted traffic classification suffer from low accuracy. In this paper, we propose a certificate-aware encrypted traffic classification method based on the Second-Order Markov Chain. We start by exploring reasons why existing methods not perform well, and make a novel observation that certificate packet length in SSL/TLS sessions contributes to application discrimination. To increase the diversity of application fingerprints, we develop a new model by incorporating the certificate packet length clustering into the Second-Order homogeneous Markov chains. Extensive evaluation results show that the proposed method lead to a 30% improvement on average compared with the state-of-the-art method, in terms of classification accuracy.

源语言英语
主期刊名2016 IEEE/ACM 24th International Symposium on Quality of Service, IWQoS 2016
出版商Institute of Electrical and Electronics Engineers Inc.
ISBN(电子版)9781509026340
DOI
出版状态已出版 - 13 10月 2016
活动24th IEEE/ACM International Symposium on Quality of Service, IWQoS 2016 - Beijing, 中国
期限: 20 6月 201621 6月 2016

出版系列

姓名2016 IEEE/ACM 24th International Symposium on Quality of Service, IWQoS 2016

会议

会议24th IEEE/ACM International Symposium on Quality of Service, IWQoS 2016
国家/地区中国
Beijing
时期20/06/1621/06/16

指纹

探究 'Certificate-aware encrypted traffic classification using Second-Order Markov Chain' 的科研主题。它们共同构成独一无二的指纹。

引用此