首页> 外文会议>Network Traffic Measurement and Analysis Conference >How HTTP/2 is changing web traffic and how to detect it
【24h】

How HTTP/2 is changing web traffic and how to detect it

机译:HTTP / 2如何更改Web流量以及如何检测到它

获取原文

摘要

HTTP constitutes a dominant part of the Internet traffic. Today's web traffic mostly consists of HTTP/1 and the much younger HTTP/2. As the traffic of both protocols is increasingly exchanged over encryption, discerning which flows in the network belong to each protocol is getting harder. Identifying flows per protocol is however very important, e.g., for building traffic models for simulations and benchmarking, and enabling operators and researchers to track the adoption of HTTP/2. This paper makes two contributions. First, using datasets of passive measurements collected in operational networks and Deep Packet Inspection (DPI), we characterize differences in HTTP/1 and HTTP/2 traffic. We show that the adoption of HTTP/2 among major providers is high and growing. Moreover, when comparing the same services over HTTP/1 or HTTP/2, we notice that HTTP/2 flows are longer, but formed by smaller packets. This is likely a consequence of new HTTP/2 features and the reorganization of servers and clients to profit from such features. Second, we present a lightweight method for the classification of encrypted web traffic into appropriate HTTP versions. In order to make the method practically feasible, we use machine learning with basic information commonly available in aggregated flow traces (e.g., NetFlow records). We show that a small labeled dataset is sufficient for training the system, and it accurately classifies traffic for several months, potentially from different measurement locations, without the need for retraining. Therefore, the method is simple, scalable, and applicable to scenarios where DPI is not possible.
机译:HTTP构成了互联网流量的主要部分。今天的Web流量主要由HTTP / 1和更年轻的HTTP / 2组成。由于两种协议的流量越来越多地交换加密,因此在网络中流出的辨别物属于每个协议的流动越来越难。然而,每个协议的识别流是非常重要的,例如,用于构建用于模拟和基准测试的流量模型,使运营商和研究人员能够跟踪HTTP / 2的采用。本文有两项贡献。首先,使用在操作网络中收集的被动测量数据集和深度分组检查(DPI),我们在HTTP / 1和HTTP / 2流量中表征差异。我们表明,主要供应商中的HTTP / 2采用高,增长。此外,在HTTP / 1或HTTP / 2上比较相同的服务时,我们会注意到HTTP / 2流程较长,但由较小的数据包形成。这可能是新的HTTP / 2功能以及服务器和客户的重组从这些功能中获利的后果。其次,我们向适当的HTTP版本介绍了一种将加密Web流量分类的轻量级方法。为了使方法实际上是可行的,我们使用机器学习与汇总流程迹线中常用的基本信息(例如,NetFlow记录)。我们表明,一个小标记的数据集足以训练系统,并且它可以准确地对流量分类数月,可能来自不同的测量位置,而无需再培训。因此,该方法简单,可扩展,并且适用于DPI无法实现的场景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号