|
|
AHybrid Method based on Statistical Features and Packet Content Analysis to Identify Major Network Tunneling Protocols
|
|
|
|
|
نویسنده
|
kazemi keihan ,fanian ali
|
منبع
|
journal of computing and security - 2016 - دوره : 3 - شماره : 2 - صفحه:95 -110
|
چکیده
|
Network trac identi cation is an essential component for e ective network analysis and management. signature-based and machine learning techniques are the two most important methods in network trac analysis. due to the strengths and weaknesses of these two approaches, their combination can strengthen them and remove the weaknesses of each in detection process. in this article, a hybrid method is introduced, to identify major network tunneling protocols. this method can detect the well-known tunneling protocols by combining signature-based methods and statistical analysis techniques through a clustering algorithm. in this proposed method, the clustering process is re ned by the feedback of signature-base method. since, in semi-supervised clustering, it is important to gain most informative data to improve the clustering performance, in the proposed clustering method, a new active learning approach is introduced for selecting informative constraints. in this hybrid method, four tunneling protocols (l2tp, pptp, ipsec and openvpn) are applied. the obtained results indicate that this proposed hybrid method signi cantly increases accuracy and cluster purity, and these protocols are identi ed with high accuracy and low processing cost.
|
کلیدواژه
|
Traffic Detection ,Tunneling Protocols ,Packet Payload Analysis ,Semi-Supervised Clustering ,Active Learning
|
آدرس
|
isfahan university of technology (iut), department of electrical and computer engineering, ایران, isfahan university of technology (iut), department of electrical and computer engineering, ایران
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|