首页> 外文会议>IEEE Global Communications Conference >BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic Classification
【24h】

BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic Classification

机译:BitCoding:交通分类的协议类型无可争议的鲁棒位级别签名

获取原文

摘要

Traffic classification has received considerable interest as many network applications use obfuscation methods to hide their identity and bypass security. Traditionally application signatures are generated using byte level content of application flows. Increasingly new data formats are used to encode the application protocols which render the byte level signatures ineffective in identifying applications. To address this issue we propose BitCoding a bit-level application signature generation using invariant bits of application flows. Unlike other works, BitCoding uses only a small number of initial bits of flows to generate signature and signature bits are encoded using run length coding to reduce size; hence it is very inexpensive in storage and is light weight for signature matching. We evaluate BitCoding using three different datasets and show that it is able to classify both text based and binary protocols with high accuracy, making it protocol type agnostic. Further we perform cross evaluation of signatures generated to understand the portability of signatures generated to other sites and conclude that it will lead to a small compromise in the detection rate.
机译:随着许多网络应用程序使用混淆方法来隐藏其身份和绕过安全性,流量分类已获得相当大的兴趣。传统上使用应用程序流的字节级别内容生成传统上应用签名。越来越多的数据格式用于对应用协议进行编码,该应用程序协议使字节级别签名呈现识别应用程序中的无效。要解决此问题,我们将使用不变的应用程序流程提出位级应用签名生成。与其他作品不同,BitCoding仅使用少量流动流量来生成签名,并且使用运行长度编码来编码签名位以减小尺寸;因此,在存储中非常便宜,并且签名匹配是重量轻的。我们使用三个不同的数据集进行评估位,并显示它能够以高精度对基于文本和二进制协议进行分类,使其协议类型不可知。此外,我们对生成的签名进行交叉评估,以了解到其他网站生成的签名的可移植性,并得出结论,它将导致在检测率上的小妥协。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号