Title: Using packet interarrival times for Internet traffic classification
Abstract: There are several techniques for classifying internet traffic, i.e. associating a flow of packets to the application that generated it. Among these techniques, Shallow Packet Inspection makes a decision by considering only the outermost packet header and other statistical characteristics of the packet process and, therefore, is well suited to perform classification of obfuscated or encrypted traffic. In particular, the packet arrival process is an interesting feature for traffic classification because cannot be easily obfuscated or manipulated. In this paper, we propose a novel technique using the measured burstiness of the packet sources over different time scales to distinguish among different internet applications. The effectiveness of this technique is experimentally evaluated with both synthetic data and real traffic traces. Synthetic traffic traces make it possible to give an estimation of the classification error rate that the algorithm can achieve, while experiments with real traffic data show that the most common Internet applications are identified with an error rate similar to the more intrusive Deep Packet Inspection.
Publication Year: 2011
Publication Date: 2011-10-01
Language: en
Type: article
Indexed In: ['crossref']
Access and Citation
Cited By Count: 6
AI Researcher Chatbot
Get quick answers to your questions about the article from our AI researcher chatbot