Using Deep Packet Inspection in Cyber Traffic Analysis

被引:6
|
作者
Deri, Luca [1 ]
Fusco, Francesco [2 ]
机构
[1] Ntop, Pisa, Italy
[2] IBM Res, Zurich, Switzerland
来源
PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR) | 2021年
关键词
Deep packet inspection; Encrypted traffic analysis; Open-source;
D O I
10.1109/CSR51186.2021.9527976
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years we have observed an escalation of cybersecurity attacks, which are becoming more sophisticated and harder to detect as they use more advanced evasion techniques and encrypted communications. The research community has often proposed the use of machine learning techniques to overcome the limitations of traditional cybersecurity approaches based on rules and signatures, which are hard to maintain, require constant updates, and do not solve the problems of zero-day attacks. Unfortunately, machine learning is not the holy grail of cybersecurity: machine learning-based techniques are hard to develop due to the lack of annotated data, are often computationally intensive, they can be target of hard to detect adversarial attacks, and more importantly are often not able to provide explanations for the predicted outcomes. In this paper, we describe a novel approach to cybersecurity detection leveraging on the concept of security score. Our approach demonstrates that extracting signals via deep packet inspections paves the way for efficient detection using traffic analysis. This work has been validated against various traffic datasets containing network attacks, showing that it can effectively detect network threats without the complexity of machine learning-based solutions.
引用
收藏
页码:89 / 94
页数:6
相关论文
共 50 条
  • [31] Improved deep packet inspection in data stream detection
    Chunyong Yin
    Hongyi Wang
    Xiang Yin
    Ruxia Sun
    Jin Wang
    The Journal of Supercomputing, 2019, 75 : 4295 - 4308
  • [32] Deep Packet Inspection through Virtual Platforms using System-on-Chip FPGAs
    Leon, Raquel
    Dominguez, Adrian
    Carballo, Pedro P.
    Nunez, Antonio
    2019 XXXIV CONFERENCE ON DESIGN OF CIRCUITS AND INTEGRATED SYSTEMS (DCIS), 2019,
  • [33] Hardware acceleration of regular expression repetitions in deep packet inspection
    Cronin, Brendan
    Wang, Xiaojun
    IET INFORMATION SECURITY, 2013, 7 (04) : 327 - 335
  • [34] Unsupervised Clustering of Honeypot Attacks by Deep HTTP Packet Inspection
    Aurora, Victor
    Neal, Christopher
    Proulx, Alexandre
    Cuppens, Nora Boulahia
    Cuppens, Frederic
    FOUNDATIONS AND PRACTICE OF SECURITY, PT I, FPS 2023, 2024, 14551 : 53 - 68
  • [35] Programmable SoC platform for Deep Packet Inspection using enhanced Boyer-Moore algorithm
    Dominguez, Adrian
    Carballo, Pedro P.
    Nunez, Antonio
    2017 12TH INTERNATIONAL SYMPOSIUM ON RECONFIGURABLE COMMUNICATION-CENTRIC SYSTEMS-ON-CHIP (RECOSOC), 2017,
  • [36] Deep Packet Inspection in Residential Gateways and Routers: Issues and Challenges
    Shankar, Subramanian Shiva
    Lin PinXing
    Herkersdorf, Andreas
    2014 14TH INTERNATIONAL SYMPOSIUM ON INTEGRATED CIRCUITS (ISIC), 2014, : 560 - 563
  • [37] Boundary hash for memory-efficient Deep Packet Inspection
    Artan, N. Sertac
    Bando, Masanori
    Chao, H. Jonathan
    2008 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, PROCEEDINGS, VOLS 1-13, 2008, : 1732 - 1737
  • [38] A Case for Trusted Sensors: Encryptors with Deep Packet Inspection Capabilities
    King, David
    Orlando, Gerardo
    Kohler, James
    2012 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2012), 2012,
  • [39] An index-split Bloom filter for deep packet inspection
    HUANG Kun1 & ZHANG DaFang1
    2 School of Software
    Science China(Information Sciences), 2011, 54 (01) : 23 - 37
  • [40] Deep Packet Inspection: Shaping the Internet and the Implications on Privacy and Security
    Corwin, Eric H.
    INFORMATION SECURITY JOURNAL, 2011, 20 (06): : 311 - 316