학술논문

A Hybrid Approach for Accurate Application Traffic Identification
Document Type
Conference
Source
2006 4th IEEE/IFIP Workshop on End-to-End Monitoring Techniques and Services End-to-End Monitoring Techniques and Services, 2006 4th IEEE/IFIP Workshop on. :1-8 2006
Subject
Communication, Networking and Broadcast Technologies
Telecommunication traffic
Traffic control
Peer to peer computing
Application software
Internet
Computer science
Testing
Terminology
Analytical models
Monitoring
Internet Traffic Monitoring
Application Traffic Identification
Signature Mapping
Session Behavior Mapping
Language
Abstract
The traffic dynamics of the Internet's dominant applications, such as peer-to-peer and multimedia, worsen the accuracy of the existing application traffic identification. There is a strong need for both practical and reliable identification methods with proof of accuracy. This paper proposes a hybrid approach of signature matching and session behavior mapping methods for accurate application traffic identification. In particular, the paper explores a priority-based signature matching scheme on early packet samples to replace conventional signature matching. It then uses session relationships to identify application traffic from the remaining, unidentified traffic. In validation, we present the accuracy analysis of applications using the Port Dependency Ratio (PDR) method for simulated traffic as well as real traffic.