【24h】

Detecting Skype flows in Web traffic

机译:检测Web流量中的Sk​​ype流

获取原文

摘要

Network managers face nowadays a challenging problem to detect traffic from Skype, a very popular application for VoIP communications. If no restrictive firewalls are adopted, Skype uses UDP as its preferred transport protocol, but it is known that due to its high capacity of adaptation, Skype can operate behind many firewalls and network proxies without user configuration. Behind restrictive firewalls, Skype uses Web TCP ports (80 or 443) as a fallback mechanism to delude firewalls and other network elements. This strategy renders Skype traffic disguised as Web traffic quite difficult to detect by network operators. In this paper, we propose a method to efficiently detect Skype flows hidden among Web traffic. We validate our proposal using real-world experimental data gathered at a commercial Internet Service Provider (ISP) and an academic institution. Our experimental results show a performance of around 90% detection rate of disguised Skype flows with a false positive rate of only 2%, whereas a 100% detection rate of Skype flows in Web traffic is achieved with a false positive rate limited to only 5%. We also evaluate the feasibility of our proposal in a real-time Skype detection scenario.
机译:网络经理现在面临着从Skype中检测到Skype的流量的具有挑战性的问题,这是一个非常流行的VoIP通信应用程序。如果没有采用限制性防火墙,则Skype使用UDP作为其首选传输协议,但已知由于其高容量适应性,Skype可以在许多防火墙和网络代理后面运行,而无需用户配置。在限制性防火墙后面,Skype使用Web TCP端口(80或443)作为后备机制来解除防火墙和其他网络元素。此策略将Skype流量伪装成Web流量很难被网络运营商检测。在本文中,我们提出了一种有效地检测隐藏在Web流量中的Sk​​ype流的方法。我们使用在商业互联网服务提供商(ISP)和学术机构聚集的现实世界实验数据验证我们的提案。我们的实验结果表明的伪装的Skype仅为2%的假阳性率流动约90%的检测率的性能,而Skype的一个100%的检测率在Web流量与仅限于5%的假阳性率实现流。我们还评估我们在实时Skype检测方案中提案的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号