首页> 外文会议>International symposium on research in attacks, intrusions and defenses >OTTer: A Scalable High-Resolution Encrypted Traffic Identification Engine
【24h】

OTTer: A Scalable High-Resolution Encrypted Traffic Identification Engine

机译:OTTer:可扩展的高分辨率加密流量识别引擎

获取原文

摘要

Several security applications rely on monitoring network traffic, which is increasingly becoming encrypted. In this work, we propose a pattern language to describe packet trains for the purpose of fine-grained identification of application-level events in encrypted network traffic, and demonstrate its expressiveness with case studies for distinguishing Messaging, Voice, and Video events in Facebook, Skype, Viber, and WhatsApp network traffic. We provide an efficient implementation of this language, and evaluate its performance by integrating it into our proprietary DPI system. Finally, we demonstrate that the proposed pattern language can be mined from traffic samples automatically, minimizing the otherwise high ruleset maintenance burden.
机译:几个安全应用程序依赖于监视网络流量,该流量正变得越来越加密。在这项工作中,我们提出了一种模式语言来描述数据包序列,以细粒度地识别加密网络流量中的应用程序级事件,并通过区分Facebook中的消息,语音和视频事件的案例研究来展示其表达力, Skype,Viber和WhatsApp网络流量。我们提供了这种语言的有效实现,并通过将其集成到我们专有的DPI系统中来评估其性能。最后,我们证明了可以从流量样本中自动提取建议的模式语言,从而最大程度地减少了规则集维护负担。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号