• Complex
  • Title
  • Author
  • Keyword
  • Abstract
  • Scholars
Search

Author:

Qin, Tao (Qin, Tao.) | Wang, Lei (Wang, Lei.) | Liu, Zhaoli (Liu, Zhaoli.) | Guan, Xiaohong (Guan, Xiaohong.)

Indexed by:

SCIE EI Scopus

Abstract:

Application identification plays an essential role in network management such as intrusion detection and security monitoring. But the continuous growth of bandwidth and massive amount of packets pose serious challenges for efficacious and accurate application identification. In this paper, we develop a new method to reduce the number of packets being processed while achieving the goal of accurate P2P and VoIP application identification. Firstly, we employ the Bi-flow model to aggregate traffic packets into Bi-flow, which can capture the exchange behavior characteristics between different terminals. Then we employ the signature of Packet Size Distribution (PSD) to capture flow dynamics, which is defined as the payload length distribution probability of the packets in one Bi-flow. Secondly, we collect PSD of several different P2P and VoIP applications and the analysis results show that PSD of different applications are different with each other, which can be used as features to perform traffic identification. We also find the PSD characteristics of one Bi-flow can be captured by its first few packets, which demonstrate our methods can identify the Bi-flow,quickly after its establishment. We employ the Renyi cross entropy to perform identification by calculating the similarity between PSD of the Bi-flow being identified and that of specific application. If the similarity is higher than a selected threshold, the Bi-flow being identified is classified to the specific application. Finally, as the PSD is a type of probability feature which is not sensitive to packet lose, we integrate the Poisson sampling method into our framework to process the massive data in backbone networks. Experimental results using the artificial and actual traces collected from monitoring platform in the Northwest Center of CERNET (China Education and Research Network) verify the accuracy and robustness of our method. (C) 2015 Elsevier B.V. All rights reserved.

Keyword:

Application identification Backbone network P2P and VoIP Packet Size Distribution Robustness Sampling method

Author Community:

  • [ 1 ] [Qin, Tao; Wang, Lei; Liu, Zhaoli; Guan, Xiaohong] Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China
  • [ 2 ] [Guan, Xiaohong] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
  • [ 3 ] [Guan, Xiaohong] Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China
  • [ 4 ] [Qin, Tao]Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China
  • [ 5 ] [Wang, Lei]Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China
  • [ 6 ] [Liu, Zhaoli]Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China
  • [ 7 ] [Guan, Xiaohong]Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China
  • [ 8 ] [Guan, Xiaohong]Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
  • [ 9 ] [Guan, Xiaohong]Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China

Reprint Author's Address:

  • Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Peoples R China.

Show more details

Related Keywords:

Source :

KNOWLEDGE-BASED SYSTEMS

ISSN: 0950-7051

Year: 2015

Volume: 82

Page: 152-162

3 . 3 2 5

JCR@2015

8 . 0 3 8

JCR@2020

ESI Discipline: COMPUTER SCIENCE;

ESI HC Threshold:138

JCR Journal Grade:2

CAS Journal Grade:2

Cited Count:

WoS CC Cited Count: 24

SCOPUS Cited Count: 42

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 7

FAQ| About| Online/Total:739/168450434
Address:XI'AN JIAOTONG UNIVERSITY LIBRARY(No.28, Xianning West Road, Xi'an, Shaanxi Post Code:710049) Contact Us:029-82667865
Copyright:XI'AN JIAOTONG UNIVERSITY LIBRARY Technical Support:Beijing Aegean Software Co., Ltd.