首页> 外文会议>10th internet measurement conference 2010 >Digging into HTTPS: Flow-Based Classification of Webmail Traffic
【24h】

Digging into HTTPS: Flow-Based Classification of Webmail Traffic

机译:深入研究HTTPS:基于流的Webmail通信量分类

获取原文
获取原文并翻译 | 示例

摘要

Recently, webmail interfaces, e.g., Horde, Outlook Web Access, and webmail platforms such as GMail, Yahoo!, and Hotmail have seen a tremendous boost in popularity. Given the importance of e-mail for personal and business use alike, and its exposure to imminent threats, there exists the need for a comprehensive view of the Internet mail system, including webmail traffic. In this paper we propose a novel, passive approach to identify webmail traffic solely based on network-level data in order to obtain a comprehensive view of the mail system. Key to our approach is that we leverage correlations across protocols and time to introduce novel features for HTTPS webmail classification: First, webmail servers tend to reside close to legacy IMAP and POP mail servers, which are easy to identify. Second, the usage of webmail services results in distinct patterns on sessions' duration and on the diurnal/weekly traffic usage profile. Third, traffic flows to webmail platforms exhibit inherent periodicities since AJAX-based clients periodically check for new messages. We use these features to build a simple classifier and detect webmail traffic on real-world NetFlow traces from a medium-sized backbone network. We believe that the major contribution of this paper - exploring a set of new features that could classify applications that run over HTTPS ports solely based on NetFlow data - will stimulate more general advance in the field of traffic classification.
机译:最近,Webmail界面(例如Horde,Outlook Web Access)和Webmail平台(例如GMail,Yahoo!和Hotmail)的受欢迎程度大大提高。考虑到电子邮件对于个人和企业用途的重要性,以及其面临的迫在眉睫的威胁,有必要对包括网络邮件流量在内的Internet邮件系统进行全面的了解。在本文中,我们提出了一种新颖的被动方法,仅基于网络级数据来识别Web邮件流量,以便获得邮件系统的全面视图。该方法的关键是,我们利用协议之间和时间上的相关性来引入HTTPS网络邮件分类的新功能:首先,网络邮件服务器往往位于易于识别的传统IMAP和POP邮件服务器附近。其次,Webmail服务的使用导致会话持续时间和每日/每周流量使用情况配置文件的模式截然不同。第三,由于基于AJAX的客户端会定期检查新邮件,因此流向Webmail平台的流量表现出固有的周期性。我们使用这些功能来构建简单的分类器,并从中型骨干网络检测真实NetFlow跟踪上的网络邮件流量。我们相信,本文的主要贡献-探索一套可以对仅基于NetFlow数据运行在HTTPS端口上的应用程序进行分类的新功能-将刺激流量分类领域的更广泛进步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号