首页> 外文会议>IEEE Global Communications Conference >BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic Classification
【24h】

BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic Classification

机译:BitCoding:用于流量分类的协议类型不可知的稳健比特级别签名

获取原文

摘要

Traffic classification has received considerable interest as many network applications use obfuscation methods to hide their identity and bypass security. Traditionally application signatures are generated using byte level content of application flows. Increasingly new data formats are used to encode the application protocols which render the byte level signatures ineffective in identifying applications. To address this issue we propose BitCoding a bit-level application signature generation using invariant bits of application flows. Unlike other works, BitCoding uses only a small number of initial bits of flows to generate signature and signature bits are encoded using run length coding to reduce size; hence it is very inexpensive in storage and is light weight for signature matching. We evaluate BitCoding using three different datasets and show that it is able to classify both text based and binary protocols with high accuracy, making it protocol type agnostic. Further we perform cross evaluation of signatures generated to understand the portability of signatures generated to other sites and conclude that it will lead to a small compromise in the detection rate.
机译:由于许多网络应用程序都使用混淆方法来隐藏其身份并绕过安全性,因此流量分类已经引起了人们的极大兴趣。传统上,应用程序签名是使用应用程序流的字节级内容生成的。越来越多的新数据格式用于对应用程序协议进行编码,从而使字节级签名在识别应用程序时失效。为了解决这个问题,我们建议使用应用程序流的不变位对BitCoding进行位级别的应用程序签名生成。与其他工作不同,BitCoding仅使用少量的流初始位来生成签名,并且使用游程长度编码对签名位进行编码以减小大小;因此,它的存储成本非常低廉,而且签名匹配的重量也很轻。我们使用三个不同的数据集对BitCoding进行了评估,结果表明它能够对基于文本的协议和二进制协议进行高精度分类,从而使其与协议类型无关。此外,我们对生成的签名进行交叉评估,以了解生成的签名对其他站点的可移植性,并得出结论,这将导致检测率的小幅折衷。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号