Two-Phased Method for Identifying SSH Encrypted Application Flows

被引:0
|
作者
Hirvonen, Matti [1 ]
Sailio, Mirko [1 ]
机构
[1] VTT Tech Res Ctr Finland, Oulu, Finland
关键词
Traffic monitoring; K-means; SSH analysis;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The use of application-layer tunnels has become more popular nowadays. By using encrypted tunnels for prohibited application such as peer-to-peer file sharing it is easy to gain access to restricted networks. Application-layer tunnels provide a possibility to bypass network defenses which is even more useful for malicious users trying to avoid detection. The accurate identification of application flows in encrypted tunnels is important for the network security and management purposes. Traditional network traffic classification methods based on port numbers or pattern-matching mechanisms are practically useless in identifying application flows inside an encrypted tunnel, therefore another approach is needed. In this paper, we propose a two-phased method for classifying SSH tunneled application flows in real time. The classification is based on the statistical features of the network flows. The first classification phase identifies the SSH connection while the second classification phase detects the tunneled application. A simple K-Means clustering algorithm is utilized in classification. We evaluated our method using manually generated packet traces. The results were promising; over 94% of all flow samples were classified correctly, while untrained application flow samples were detected as unknown at high precision.
引用
收藏
页码:1033 / 1038
页数:6
相关论文
共 50 条
  • [31] Supporting Universal Prevention Programs: A Two-Phased Coaching Model
    Becker, Kimberly D.
    Darney, Dana
    Domitrovich, Celene
    Keperling, Jennifer Pitchford
    Ialongo, Nicholas S.
    CLINICAL CHILD AND FAMILY PSYCHOLOGY REVIEW, 2013, 16 (02) : 213 - 228
  • [32] A two-phased object orientation controller on soft finger operations
    Inoue, Takahiro
    Hirai, Shinichi
    2007 IEEE/RSJ INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS, VOLS 1-9, 2007, : 2534 - +
  • [33] Complex interactions in Parkinson's disease: A two-phased approach
    Maraganore, DM
    de Andrade, M
    Lesnick, TG
    Farrer, MJ
    Bower, JH
    Hardy, JA
    Rocca, WA
    MOVEMENT DISORDERS, 2003, 18 (06) : 631 - 636
  • [34] On Internet Traffic Classification: A Two-Phased Machine Learning Approach
    Bakhshi, Taimur
    Ghita, Bogdan
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2016, 2016
  • [35] Supporting Universal Prevention Programs: A Two-Phased Coaching Model
    Kimberly D. Becker
    Dana Darney
    Celene Domitrovich
    Jennifer Pitchford Keperling
    Nicholas S. Ialongo
    Clinical Child and Family Psychology Review, 2013, 16 : 213 - 228
  • [36] Two-phased bulk insertion by seeded clustering for R-trees
    Lee, T
    Lee, S
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2006, E89D (01): : 228 - 236
  • [37] Two-Phased Real-Time Rendering of Large Neuron Databases
    Ciechomski, Pablo de Heras
    Mange, Robin
    Peternier, Achille
    IIT: 2008 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION TECHNOLOGY, 2008, : 737 - 741
  • [38] A Two-phased Risk Management Framework Targeting SMEs Project Portfolios
    Ponsard, Christophe
    Germeau, Fabian
    Ospina, Gustavo
    Bitter, Jan
    Mende, Hendrik
    Vossen, Rene
    Schmitt, Robert H.
    SIMULTECH: PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON SIMULATION AND MODELING METHODOLOGIES, TECHNOLOGIES AND APPLICATIONS, 2019, 2019, : 406 - 413
  • [39] Reduced exchange coupling and hysteresis loops in two-phased magnetic nanosystem
    Deng, Y.
    Zhao, G. P.
    Chen, L.
    Zhang, H. W.
    Zhou, X. L.
    JOURNAL OF MAGNETISM AND MAGNETIC MATERIALS, 2011, 323 (05) : 535 - 538
  • [40] A two-phased perishable inventory model for production planning in a food industry
    Shin, Moonsoo
    Lee, Hwaseop
    Ryu, Kwangyeol
    Cho, Yongju
    Son, Young-Jun
    COMPUTERS & INDUSTRIAL ENGINEERING, 2019, 133 : 175 - 185