Otter: A Scalable High-Resolution Encrypted Traffic Identification Engine

RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, RAID 2018(2018)

引用 27|浏览103
暂无评分
摘要
Several security applications rely on monitoring network traffic, which is increasingly becoming encrypted. In this work, we propose a pattern language to describe packet trains for the purpose of fine-grained identification of application-level events in encrypted network traffic, and demonstrate its expressiveness with case studies for distinguishing Messaging, Voice, and Video events in Facebook, Skype, Viber, and WhatsApp network traffic. We provide an efficient implementation of this language, and evaluate its performance by integrating it into our proprietary DPI system. Finally, we demonstrate that the proposed pattern language can be mined from traffic samples automatically, minimizing the otherwise high ruleset maintenance burden.
更多
查看译文
关键词
Traffic analysis, OTT applications, Network monitoring
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要