Efficient Keyword Matching for Deep Packet Inspection based Network Traffic Classification

被引:0
作者
Khandait, Pratibha [1 ]
Hubballi, Neminath [1 ]
Mazumdar, Bodhisatwa [1 ]
机构
[1] Indian Inst Technol Indore, Discipline Comp Sci & Engn, Indore, Madhya Pradesh, India
来源
2020 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS) | 2020年
关键词
Network Traffic Classification; Deep Packet Inspection; String Matching; State Transition Machine;
D O I
10.1109/comsnets48256.2020.9027353
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network traffic classification has a range of applications in network management including QoS and security monitoring. Deep Packet Inspection (DPI) is one of the effective method used for traffic classification. DPI is computationally expensive operation involving string matching between payload and application signatures. Existing traffic classification techniques perform multiple scans of payload to classify the application flows - first scan to extract the words and the second scan to match the words with application signatures. In this paper we propose an approach which can classify network flows with single scan of flow payloads using a heuristic method to achieve a sub-linear search complexity. The idea is to scan few initial bytes of payload and determine potential application signature(s) for subsequent signature matching. We perform experiments with a large dataset containing 171873 network flows and show that it has a good classification accuracy of 98%.
引用
收藏
页数:4
相关论文
共 50 条
  • [31] Optimizing Deep Packet Inspection for High-Speed Traffic Analysis
    Cascarano, Niccolo
    Ciminiera, Luigi
    Risso, Fulvio
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2011, 19 (01) : 7 - 31
  • [32] Towards the Detection of Encrypted BitTorrent Traffic through Deep Packet Inspection
    Carvalho, David A.
    Pereira, Manuela
    Freire, Mario M.
    [J]. SECURITY TECHNOLOGY, PROCEEDINGS, 2009, 58 : 265 - 272
  • [33] Optimizing Deep Packet Inspection for High-Speed Traffic Analysis
    Niccolò Cascarano
    Luigi Ciminiera
    Fulvio Risso
    [J]. Journal of Network and Systems Management, 2011, 19 : 7 - 31
  • [34] Boundary hash for memory-efficient Deep Packet Inspection
    Artan, N. Sertac
    Bando, Masanori
    Chao, H. Jonathan
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, PROCEEDINGS, VOLS 1-13, 2008, : 1732 - 1737
  • [35] Efficient regular expression compression algorithm for deep packet inspection
    Xu, Qian
    Y.-P., et al.
    Ge, Jing-Guo
    Qian, Hua-Lin
    [J]. Ruan Jian Xue Bao/Journal of Software, 2009, 20 (08): : 2214 - 2226
  • [36] An Online Network Traffic Classification Method Based on Deep Learning
    Liao, Qing
    Li, Tianqi
    Zhang, Wei
    [J]. PROCEEDINGS OF 2019 IEEE 2ND INTERNATIONAL CONFERENCE ON ELECTRONIC INFORMATION AND COMMUNICATION TECHNOLOGY (ICEICT 2019), 2019, : 34 - 39
  • [37] Fine-grained parallel regular expression matching for deep packet inspection
    [J]. Liu, X. (xingkuiliu@ncic.ac.cn), 1600, Science Press (51): : 1061 - 1070
  • [38] A Multiple Simple Regular Expression Matching Architecture and Coprocessor for Deep Packet Inspection
    Zhang, Wei
    Xue, Yibo
    Wang, Dongsheng
    Song, Tian
    [J]. 2008 13TH ASIA-PACIFIC COMPUTER SYSTEMS ARCHITECTURE CONFERENCE, 2008, : 245 - +
  • [39] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Lotfollahi, Mohammad
    Siavoshani, Mahdi Jafari
    Zade, Ramin Shirali Hossein
    Saberian, Mohammdsadegh
    [J]. SOFT COMPUTING, 2020, 24 (03) : 1999 - 2012
  • [40] Deep packet: a novel approach for encrypted traffic classification using deep learning
    Mohammad Lotfollahi
    Mahdi Jafari Siavoshani
    Ramin Shirali Hossein Zade
    Mohammdsadegh Saberian
    [J]. Soft Computing, 2020, 24 : 1999 - 2012