Two-Phased Method for Identifying SSH Encrypted Application Flows

被引:0
|
作者
Hirvonen, Matti [1 ]
Sailio, Mirko [1 ]
机构
[1] VTT Tech Res Ctr Finland, Oulu, Finland
关键词
Traffic monitoring; K-means; SSH analysis;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The use of application-layer tunnels has become more popular nowadays. By using encrypted tunnels for prohibited application such as peer-to-peer file sharing it is easy to gain access to restricted networks. Application-layer tunnels provide a possibility to bypass network defenses which is even more useful for malicious users trying to avoid detection. The accurate identification of application flows in encrypted tunnels is important for the network security and management purposes. Traditional network traffic classification methods based on port numbers or pattern-matching mechanisms are practically useless in identifying application flows inside an encrypted tunnel, therefore another approach is needed. In this paper, we propose a two-phased method for classifying SSH tunneled application flows in real time. The classification is based on the statistical features of the network flows. The first classification phase identifies the SSH connection while the second classification phase detects the tunneled application. A simple K-Means clustering algorithm is utilized in classification. We evaluated our method using manually generated packet traces. The results were promising; over 94% of all flow samples were classified correctly, while untrained application flow samples were detected as unknown at high precision.
引用
收藏
页码:1033 / 1038
页数:6
相关论文
共 50 条
  • [21] Angular dependence of magnetic reversal in two-phased nanolayers
    Zhao, G. P.
    Zhou, G.
    Zhang, H. W.
    Feng, Y. P.
    Xian, C. W.
    Zhang, Q. X.
    COMPUTATIONAL MATERIALS SCIENCE, 2008, 44 (01) : 117 - 121
  • [22] Identifying influence patterns of regional agricultural drought vulnerability using a two-phased grey rough combined model
    Sun, Huifang
    Fang, Liping
    Dang, Yaoguo
    Mao, Wenxin
    GREY SYSTEMS-THEORY AND APPLICATION, 2022, 12 (01) : 230 - 251
  • [23] Micromechanics predictions for two-phased nanocomposites and three-phased multiscale composites: A review
    Armbrister, Chelsea E. E.
    Okoli, Okenwa I.
    Shanbhag, Sachin
    JOURNAL OF REINFORCED PLASTICS AND COMPOSITES, 2015, 34 (08) : 605 - 623
  • [24] Detecting and prioritizing product defects using social media data and the two-phased QFD method
    Zheng, Lu
    He, Zhen
    He, Shuguang
    COMPUTERS & INDUSTRIAL ENGINEERING, 2023, 177
  • [25] A Two-Phased Fuzzy Decision Making Procedure for IT Supplier Selection
    Shohaimay, Fairuz
    Ramli, Nazirah
    Mohamed, Siti Rosiah
    Mohd, Ainun Hafizah
    INTERNATIONAL CONFERENCE ON MATHEMATICAL SCIENCES AND STATISTICS 2013 (ICMSS2013), 2013, 1557 : 411 - 415
  • [26] Two-phased strategy for improvement of breast cancer care in Bangladesh
    Sarker, M.
    Faruque, G.
    Rahman, M. M.
    BREAST, 2021, 56 : S58 - S58
  • [27] A Two-Phased Evolutionary Approach for Intelligent Task Assignment & Scheduling
    Lo, Chih-Chung
    Yu, Shih-Wei
    2015 11TH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION (ICNC), 2015, : 1092 - 1097
  • [28] A two-phased heuristic for relation-based item location
    Wutthisirisart, Phichet
    Noble, James S.
    Chang, C. Alec
    COMPUTERS & INDUSTRIAL ENGINEERING, 2015, 82 : 94 - 102
  • [29] Torsion of a Two-Phased Composite Bar With Helical Distribution of Constituents
    Jopek, Hubert
    Strek, Tomasz
    PHYSICA STATUS SOLIDI B-BASIC SOLID STATE PHYSICS, 2017, 254 (12):
  • [30] Two-phased SVPWM based on H-bridged structure
    Sun, L
    Kang, EL
    Gao, HY
    2003 IEEE INDUSTRY APPLICATIONS CONFERENCE, VOLS 1-3: CROSSROADS TO INNOVATIONS, 2003, : 1730 - 1734