KeyClass: Efficient keyword matching for network traffic classification

被引:10
|
作者
Hubballi, Neminath [1 ]
Khandait, Pratibha [1 ]
机构
[1] Indian Inst Technol Indore, Dept Comp Sci & Engn, Indore, Madhya Pradesh, India
关键词
Network traffic classification; Deep Packet Inspection; Efficient keyword matching;
D O I
10.1016/j.comcom.2021.12.021
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network traffic classification is required for a range of network management activities like meeting the Quality of Service demands of applications and security monitoring. Deep Packet Inspection (DPI) based methods achieve better classification accuracy compared to other techniques. However, DPI is computationally demanding and requires searching patterns in the payload. Methods found in the literature suffer from performance issues as they perform multiple scans of payload. In this paper, we describe KeyClass, which is a DPI based traffic classifier and can classify network flows with single scan of payload using keyword based signatures. KeyClass achieves performance gains (speed of classification) with a combination of two things. It quickly identifies potential application(s) by scanning few initial bytes of payload and optimize the number of character comparisons while searching remaining keywords of potential application(s). In order to identify potential applications, it uses a finite state machine constructed with first keyword of every application using classic Aho-Corasick multi-pattern matching algorithm. KeyClass has an application specific signature which is generated with the remaining set of keywords of an application. By skipping portions of payload from inspection, coupled with an efficient string matching algorithm, it practically achieves sub-linear search complexity. We evaluate the classification and execution performance of KeyClass with experiments using two large datasets containing 173619 and 885405 network flows and report that it has a good average classification accuracy of approximate to 98%. In our evaluation, KeyClass is found to be 3.79 times faster than state of the art methods.
引用
收藏
页码:79 / 91
页数:13
相关论文
共 50 条
  • [41] An Efficient Episode Matching For Network Security
    Zhang, Ruhui
    Du, Ye
    Wang, Xing
    Zhao, Bin
    2011 SECOND INTERNATIONAL CONFERENCE ON INFORMATION, COMMUNICATION AND EDUCATION APPLICATION (ICEA 2011), 2011, : 73 - +
  • [42] Partial matching : An efficient form classification method
    Byun, Y
    Choi, Y
    Kim, G
    Lee, Y
    DOCUMENT RECOGNITION AND RETRIEVAL VIII, 2001, 4307 : 341 - 352
  • [43] MTT: an efficient model for encrypted network traffic classification using multi-task transformer
    Weiping Zheng
    Jianhao Zhong
    Qizhi Zhang
    Gansen Zhao
    Applied Intelligence, 2022, 52 : 10741 - 10756
  • [44] Multi-task Aware Resource Efficient Traffic Classification via In-Network Inference
    Yoon, Seongyeon
    Kim, Heewon
    Jeong, Hyeonjae
    Bae, Chanbin
    Kim, Haeun
    Pack, Sangheon
    PROCEEDINGS OF THE 2024 SIGCOMM WORKSHOP ON NETWORKS FOR AI COMPUTING, NAIC 2024, 2024, : 69 - 74
  • [45] MTT: an efficient model for encrypted network traffic classification using multi-task transformer
    Zheng, Weiping
    Zhong, Jianhao
    Zhang, Qizhi
    Zhao, Gansen
    APPLIED INTELLIGENCE, 2022, 52 (09) : 10741 - 10756
  • [46] Efficient Classification of Enciphered SCADA Network Traffic in Smart Factory Using Decision Tree Algorithm
    Ahakonye, Love Allen Chijioke
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae-Min
    Kim, Dong-Seong
    IEEE ACCESS, 2021, 9 : 154892 - 154901
  • [47] FILE DETECTION ON NETWORK TRAFFIC USING APPROXIMATE MATCHING
    Breitinger, Frank
    Baggili, Ibrahim
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2014, 9 (02) : 23 - 35
  • [48] An ICS Traffic Classification Based on Industrial Control Protocol Keyword Feature Extraction Algorithm
    Yu, Changhong
    Zhang, Ze
    Gao, Ming
    APPLIED SCIENCES-BASEL, 2022, 12 (21):
  • [49] Traffic flow stabilized by matching speed on network with a bottleneck
    Nagatani, Takashi
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2020, 538
  • [50] Keyword spotting on Korean document images by matching the keyword image
    Kim, SH
    Park, SC
    Jeong, CB
    Kim, JS
    Park, HR
    Lee, GS
    DIGITAL LIBRARIES: IMPLEMENTING STRATEGIES AND SHARING EXPERIENCES, PROCEEDINGS, 2005, 3815 : 158 - 166