Classification of Encrypted Internet Traffic Using Kullback Leibler Divergence and Euclidean Distance - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2020

Classification of Encrypted Internet Traffic Using Kullback Leibler Divergence and Euclidean Distance

Résumé

The limitations of traditional classification methods based on port number and payload inspection to classify encrypted or obfus-cated Internet traffic, often with randomized port numbers, have lead to significant research efforts focusing on classification approaches based on Machine Learning techniques using Transport Layer statistical features. However, these approaches also have their own limitations, leading to the study of a set of other alternative approaches, including statistics-based approaches. Statistical approaches can be an alternative to machine learning, because in real-time traffic classification with new types of data, the entire traffic classifier has to be retrained in order to adapt to the new change by combining the old training data with the new training data. This article investigates the classification of encrypted traffic using statistical methods applied to network traffic classification. We propose two statistical classifiers for encrypted Internet traffic based on Kullback Leibler divergence and Euclidean distance, which are computed using the flow and packet size obtained from some of the protocols used by applications. In our experiments, we evaluate the two classifiers based on statistical methods and compare them with a classifier based on Support Vector Machine (SVM). During our study, we were able to classify the traffic by using few features without compromising the performance of the classifier. The experimental results illustrate the effectiveness of our models used for traffic classification.
Fichier principal
Vignette du fichier
cunha-aina2020.pdf (379.53 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02493390 , version 1 (27-02-2020)

Identifiants

  • HAL Id : hal-02493390 , version 1

Citer

Vanice Canuto Cunha, Arturo Zavala, Pedro Inácio, Damien Magoni, Mário M. Freire. Classification of Encrypted Internet Traffic Using Kullback Leibler Divergence and Euclidean Distance. 34th International Conference on Advanced Information Networking and Applications, Apr 2020, Caserta, Italy. ⟨hal-02493390⟩

Collections

CNRS
78 Consultations
259 Téléchargements

Partager

Gmail Facebook X LinkedIn More