TY - GEN
T1 - Traffic classification - Towards accurate real time network applications
AU - Li, Zhu
AU - Yuan, Ruixi
AU - Guan, Xiaohong
PY - 2007
Y1 - 2007
N2 - Timely traffic identification is critical in network security monitoring and traffic engineering. Traditional methods using well-known ports, protocols and precise signature matching are no longer accurate with the proliferation of new applications. Recently, applying pattern recognition methods to classify network application traffic based on the flow parameters (e.g. port, flow duration, etc.) has become increasing popular. However, many methods developed in the previous works are either too complex to be applied in real-time, or suffer from lower accuracy due to the insufficient knowledge of the application. In this paper, we first give an overview on the developments of pattern recognition methods as traffic classification tools. We then develop two separate pattern recognition methods: one with supervised learning, and one with un-supervised learning, and apply them to classify traffic captured from a campus backbone network. The supervised learning method (an optimized SVM method) yields approximately 99.41% accuracy for the collected traffic. The un-supervised learning method (an entropy based clustering method) gets the average accuracy of 92.41% for the top 20 traffic generating hosts during the same time period. Performance test on a single PC with 3GHz Pentium 4 processors and IGB of memory show that both methods can handle more than 10000 network flows per second, close to real time requirements for many situations.
AB - Timely traffic identification is critical in network security monitoring and traffic engineering. Traditional methods using well-known ports, protocols and precise signature matching are no longer accurate with the proliferation of new applications. Recently, applying pattern recognition methods to classify network application traffic based on the flow parameters (e.g. port, flow duration, etc.) has become increasing popular. However, many methods developed in the previous works are either too complex to be applied in real-time, or suffer from lower accuracy due to the insufficient knowledge of the application. In this paper, we first give an overview on the developments of pattern recognition methods as traffic classification tools. We then develop two separate pattern recognition methods: one with supervised learning, and one with un-supervised learning, and apply them to classify traffic captured from a campus backbone network. The supervised learning method (an optimized SVM method) yields approximately 99.41% accuracy for the collected traffic. The un-supervised learning method (an entropy based clustering method) gets the average accuracy of 92.41% for the top 20 traffic generating hosts during the same time period. Performance test on a single PC with 3GHz Pentium 4 processors and IGB of memory show that both methods can handle more than 10000 network flows per second, close to real time requirements for many situations.
KW - Network flows
KW - Patter recognition
KW - Supervised learning
KW - Traffic identification
UR - https://www.scopus.com/pages/publications/38149098651
U2 - 10.1007/978-3-540-73111-5_8
DO - 10.1007/978-3-540-73111-5_8
M3 - 会议稿件
AN - SCOPUS:38149098651
SN - 9783540731092
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 67
EP - 76
BT - Human-Computer Interaction
PB - Springer Verlag
T2 - 12th International Conference on Human-Computer Interaction, HCI International 2007
Y2 - 22 July 2007 through 27 July 2007
ER -