PTF: Passive Temporal Fingerprinting - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

PTF: Passive Temporal Fingerprinting

Résumé

We describe in this paper a tool named PTF (Passive and Temporal Fingerprinting) for fingerprinting network devices. The objective of device fingerprinting is to uniquely identify device types by looking at captured traffic from devices imple- menting that protocol. The main novelty of our approach consists in leveraging both temporal and behavioral features for this purpose. The key contribution is a fingerprinting scheme, where individual fingerprints are represented by tree-based temporal finite state machines. We have developed a fingerprinting scheme that leverages supervised learning approaches based on support vector machines for this purpose.
Fichier principal
Vignette du fichier
77728_1.pdf (365.01 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-00645299 , version 1 (27-11-2011)

Identifiants

  • HAL Id : hal-00645299 , version 1

Citer

Jérôme François, Humberto Abdelnur, Radu State, Olivier Festor. PTF: Passive Temporal Fingerprinting. 12th IFIP/IEEE International Symposium on Integrated Network Management - IM'2011, May 2011, Dublin, Ireland. 8 p. ⟨hal-00645299⟩
193 Consultations
416 Téléchargements

Partager

Gmail Facebook X LinkedIn More