Graption: A graph-based P2P traffic classification framework for the internet backbone

被引:41
作者
Iliofotou, Marios [1 ]
Kim, Hyun-Chul [2 ]
Faloutsos, Michalis [1 ]
Mitzenmacher, Michael
Pappu, Prashanth [3 ]
Varghese, George [4 ]
机构
[1] Univ Calif Riverside, Dept Comp Sci, Riverside, CA 92521 USA
[2] Seoul Natl Univ, Sch Comp Sci & Engn, Seoul, South Korea
[3] Conviva Inc, Prod Management, San Mateo, CA USA
[4] Univ Calif San Diego, San Diego, CA 92103 USA
基金
美国国家科学基金会;
关键词
Traffic classification; Behavioral-approach; Peer-to-peer; Graph mining; NETWORKS;
D O I
10.1016/j.comnet.2011.01.020
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Monitoring network traffic and classifying applications are essential functions for network administrators. Current traffic classification methods can be grouped in three categories: (a) now-based (e.g., packet sizing/timing features), (b) payload-based, and (c) host-based. Methods from all three categories have limitations, especially when it comes to detecting new applications, and classifying traffic at the backbone. In this paper, we propose the use of Traffic Dispersion Graphs (TDGs) to remedy these limitations. Given a set of flows, a TDG is a graph with an edge between any two IP addresses that communicate; thus TDGs capture network-wide interactions. Using TDGs, we develop an application classification framework dubbed Graption (Graph-based classification). Our framework provides a systematic way to classify traffic by using information from the network-wide behavior and now-level characteristics of Internet applications. As a proof of concept, we instantiate our framework to detect P2P traffic, and show that it can identify 90% of P2P flows with 95% accuracy in backbone traces, which are particularly challenging for other methods. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:1909 / 1920
页数:12
相关论文
共 50 条
[41]   Distinctive traffic characteristics of pure and game P2P applications [J].
Han, YoungTae ;
Park, HongShik .
10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, :405-408
[42]   Nearby Neighbor Selection in P2P Systems to Localize Traffic [J].
Sheng, Lijie ;
Wen, Haoyu .
2009 FOURTH INTERNATIONAL CONFERENCE ON INTERNET AND WEB APPLICATIONS AND SERVICES, 2009, :68-+
[43]   P2P based intrusion detection [J].
Czirkos, Zoltan ;
Hosszu, Gabor .
INFOCOMMUNICATIONS JOURNAL, 2009, 1 (01) :3-10
[44]   Detecting Malware with Graph-based Methods: Traffic Classification, Botnets, and Facebook Scams [J].
Faloutsos, Michalis .
PROCEEDINGS OF THE 22ND INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW'13 COMPANION), 2013, :495-496
[45]   From P2P to Cloud based P2P for Live Media streaming-A Survey [J].
Evangeline, Preetha D. ;
AnandhaKumar, P. .
2015 SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2015,
[46]   Developing an extensible framework for content based searching in super peer p2p network [J].
Islam, Muhammad Nazrul ;
Islam, Md. Ashiqul ;
Shadaque, Imani Jafar ;
Khan, Md. Razib Hayat .
PROCEEDINGS OF 10TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (ICCIT 2007), 2007, :141-145
[47]   Addressing Challenges in Browser Based P2P Content Sharing Framework Using WebRTC [J].
Vashishth, Shikhar ;
Sinha, Yash ;
Babu, K. Hari .
IEEE 30TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS IEEE AINA 2016, 2016, :850-857
[48]   Research on Education Reform of Dynamic P2P Training Framework Based on Cloud Computing [J].
Li, Yang ;
Chen, Xiang .
2013 FOURTH INTERNATIONAL CONFERENCE ON NETWORKING AND DISTRIBUTED COMPUTING (ICNDC), 2013, :41-45
[49]   A new method of P2P traffic identification based on Support Vector Machine at the host level [J].
Liu, Feng ;
Li, Zhitang ;
Nie, Qingbin .
ITCS: 2009 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND COMPUTER SCIENCE, PROCEEDINGS, VOL 2, PROCEEDINGS, 2009, :579-+
[50]   pFusion: A P2P architecture for Internet-scale content-based search and retrieval [J].
Zeinalipour-Yazti, Demetrios ;
Kalogeraki, Vana ;
Gunopulos, Dimitrios .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2007, 18 (06) :804-817