KISS: Stochastic Packet Inspection

  • Authors:
  • Alessandro Finamore;Marco Mellia;Michela Meo;Dario Rossi

  • Affiliations:
  • Politecnico di Torino,;Politecnico di Torino,;Politecnico di Torino,;TELECOM ParisTech,

  • Venue:
  • TMA '09 Proceedings of the First International Workshop on Traffic Monitoring and Analysis
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes KISS, a new Internet classification method. Motivated by the expected raise of UDP traffic volume, which stems from the momentum of P2P streaming applications, we propose a novel statistical payload-based classification framework, targeted to UDP traffic. Statistical signatures are automatically inferred from training data, by the means of a Chi-Square like test, which extracts the protocol "syntax", but ignores the protocol semantic and synchronization rules. The signatures feed a decision engine based on Support Vector Machines. KISS is tested in different scenarios, considering both data, VoIP, and traditional P2P Internet applications. Results are astonishing. The average True Positive percentage is 99.6%, with the worst case equal 98.7%. Less than 0.05% of False Positives are detected.