首页> 外文会议>International Workshop on Traffic Monitoring and Analysis >SFMap: Inferring Services over Encrypted Web Flows Using Dynamical Domain Name Graphs
【24h】

SFMap: Inferring Services over Encrypted Web Flows Using Dynamical Domain Name Graphs

机译:SFMAP:使用动态域名图形的加密Web流过度推断服务

获取原文

摘要

Most modern Internet services are carried over the web. A significant amount of web transactions is now encrypted and the transition to encryption has made it difficult for network operators to understand traffic mix. The goal of this study is to enable network operators to infer hostnames within HTTPS traffic because hostname information is useful to understand the breakdown of encrypted web traffic. The proposed approach correlates HTTPS flows and DNS queries/responses. Although this approach may appear trivial, recent deployment and implementation of DNS ecosystems have made it a challenging research problem; i.e., canonical name tricks used by CDNs, the dynamic and diverse nature of DNS TTL settings, and incomplete measurements due to the existence of various caching mechanisms. To tackle these challenges, we introduce domain name graph (DNG), which is a formal expression that characterizes the highly dynamic and diverse nature of DNS mechanisms. Furthermore, we have developed a framework called Service-Flow map (SFMap) that works on top of the DNG. SFMap statistically estimates the hostname of an HTTPS server, given a pair of client and server IP addresses. We evaluate the performance of SFMap through extensive analysis using real packet traces collected from two locations with different scales. We demonstrate that SFMap establishes good estimation accuracies and outperforms a state-of-the-art approach.
机译:大多数现代互联网服务都在网上进行。现在加密大量的Web事务,并且对加密的过渡使得网络运营商难以理解流量混合。这项研究的目标是使内HTTPS网络运营商来推断主机名流量,因为主机名信息有助于了解加密的网络流量的细分。所提出的方法将HTTPS流程和DNS查询/响应相关联。虽然这种方法可能看起来很简单,但最近的部署和实施DNS生态系统已经使其成为一个具有挑战性的研究问题;即CDN,CDNS的规范名称技巧,DNS TTL设置的动态和多样性,以及由于各种缓存机制的存在而无法完成的测量。为了解决这些挑战,我们介绍了域名图(DNG),这是一种正式表达,其特征是DNS机制的高度动态和多样性。此外,我们开发了一个名为Service-Flow Map(SFMAP)的框架,它适用于DNG的顶部。 SFMAP统计地估计HTTPS服务器的主机名,给定一对客户端和服务器IP地址。我们通过使用从两个位置收集的实际数据包迹线进行广泛的分析来评估SFMAP的性能。我们证明SFMAP建立了良好的估计精度,优于最先进的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号