Using Deep Packet Inspection in Cyber Traffic Analysis

被引:6
|
作者
Deri, Luca [1 ]
Fusco, Francesco [2 ]
机构
[1] Ntop, Pisa, Italy
[2] IBM Res, Zurich, Switzerland
来源
PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR) | 2021年
关键词
Deep packet inspection; Encrypted traffic analysis; Open-source;
D O I
10.1109/CSR51186.2021.9527976
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years we have observed an escalation of cybersecurity attacks, which are becoming more sophisticated and harder to detect as they use more advanced evasion techniques and encrypted communications. The research community has often proposed the use of machine learning techniques to overcome the limitations of traditional cybersecurity approaches based on rules and signatures, which are hard to maintain, require constant updates, and do not solve the problems of zero-day attacks. Unfortunately, machine learning is not the holy grail of cybersecurity: machine learning-based techniques are hard to develop due to the lack of annotated data, are often computationally intensive, they can be target of hard to detect adversarial attacks, and more importantly are often not able to provide explanations for the predicted outcomes. In this paper, we describe a novel approach to cybersecurity detection leveraging on the concept of security score. Our approach demonstrates that extracting signals via deep packet inspections paves the way for efficient detection using traffic analysis. This work has been validated against various traffic datasets containing network attacks, showing that it can effectively detect network threats without the complexity of machine learning-based solutions.
引用
收藏
页码:89 / 94
页数:6
相关论文
共 50 条
  • [41] A Hardware-Based String Matching Using State Transition Compression for Deep Packet Inspection
    Kim, HyunJin
    Lee, Seung-Woo
    ETRI JOURNAL, 2013, 35 (01) : 154 - 157
  • [42] SOCIETAL AND IDEOLOGICAL IMPACTS OF DEEP PACKET INSPECTION INTERNET SURVEILLANCE
    Fuchs, Christian
    INFORMATION COMMUNICATION & SOCIETY, 2013, 16 (08) : 1328 - 1359
  • [43] Efficient regular expression compression algorithm for deep packet inspection
    Xu, Qian
    Y.-P., et al.
    Ge, Jing-Guo
    Qian, Hua-Lin
    Ruan Jian Xue Bao/Journal of Software, 2009, 20 (08): : 2214 - 2226
  • [44] An index-split Bloom filter for deep packet inspection
    Huang Kun
    Zhang DaFang
    SCIENCE CHINA-INFORMATION SCIENCES, 2011, 54 (01) : 23 - 37
  • [45] A Predict Deterministic Finite Automaton for Practical Deep Packet Inspection
    Wei, Qiang
    Li, Yunzhao
    Chu, Yanjie
    2012 INTERNATIONAL WORKSHOP ON INFORMATION AND ELECTRONICS ENGINEERING, 2012, 29 : 2156 - 2161
  • [46] An index-split Bloom filter for deep packet inspection
    Kun Huang
    DaFang Zhang
    Science China Information Sciences, 2011, 54 : 23 - 37
  • [47] Hybridization of Mean Shift Clustering and Deep Packet Inspected Classification for Network Traffic Analysis
    Kumar, Sathish A. P.
    Suresh, A.
    Anand, S. Raj
    Chokkanathan, K.
    Vijayasarathy, M.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (01) : 217 - 233
  • [48] Speculative parallel pattern matching using stride-k DFA for deep packet inspection
    Najam, Maleeha
    Younis, Usman
    Rasool, Raihan Ur
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2015, 54 : 78 - 87
  • [49] Hybridization of Mean Shift Clustering and Deep Packet Inspected Classification for Network Traffic Analysis
    Sathish A. P. Kumar
    A. Suresh
    S. Raj Anand
    K. Chokkanathan
    M. Vijayasarathy
    Wireless Personal Communications, 2022, 127 : 217 - 233
  • [50] A Hardware-Efficient Pattern Matching Architecture Using Process Element Tree for Deep Packet Inspection
    Ahn, Seongyong
    Hong, Hyejeong
    Kim, HyunJin
    Ahn, Jin-Ho
    Baek, Dongmyong
    Kang, Sungho
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2010, E93B (09) : 2440 - 2442