Identification Peer-to-Peer Traffic for High Speed Networks Using Packet Sampling and Application Signatures

被引:0
作者
Guo, Zhenbin [1 ]
Qiu, Zhengding [1 ]
机构
[1] Beijing Jiaotong Univ, Inst Informat Sci, Beijing 100044, Peoples R China
来源
ICSP: 2008 9TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, VOLS 1-5, PROCEEDINGS | 2008年
关键词
peer-to-peer; traffic identification; packet sampling; application signatures; BitTorrent;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
It is very difficult to identify peer-to-peer (P2P) traffic in high speed network environment because well-known port numbers are no longer reliable and application signatures are not efficient enough. In this paper, we present a P2P traffic identification method for high speed networks using packet sampling and application signatures. Models of false negatives and false positives are developed to analyze the the effects of packet sampling probability (which is the probability of a packet to be captured when the packet passes through the monitor location) and application signatures probability (which is the probability of a packet containing application signature) on accuracy. We implemented the method with Snort by developing a flow state differentiating preprocessor. We have applied the method to identify BitTorrent traffic with 13 application signatures. The experiment results show that the efficiency and accuracy of the method are that the exciting and the method can be applied to high speed networks. The experiment results also show that the false negatives and false positives models are very accurate.
引用
收藏
页码:2014 / 2020
页数:7
相关论文
共 15 条
  • [1] *BITTORRENT ORG, PROT SPEC V1 0
  • [2] *BITTORRENT ORG, EXP DRAFT BITTORRENT
  • [3] CHOI B, 2004, IEEE GLOB TEL C 2004
  • [4] Constantinou F, 2006, NCA 2006: FIFTH IEEE INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS, PROCEEDINGS, P93
  • [5] ELSON J, TCPFLOW TCP FLOW REC
  • [6] GERALD C, ONLINE
  • [7] KARAGIANNIS T, 2004, IEEE GLOB TEL C 2004
  • [8] KARAGIANNIS T, 2004, 4 ACM SIGCOMM C INT
  • [9] MOORE AW, 2005, PASS ACT MEAS WORKSH
  • [10] PARKER A, TRUE PICTURE PEET TO