Probabilistic identification for hard to classify protocol

  • Authors:
  • Elie Bursztein

  • Affiliations:
  • LSV, ENS Cachan, CNRS, INRIA

  • Venue:
  • WISTP'08 Proceedings of the 2nd IFIP WG 11.2 international conference on Information security theory and practices: smart devices, convergence and next generation networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

With the growing use of protocols obfuscation techniques,protocol identification for Q.O.S enforcement, traffic prohibition, and intrusiondetection has became a complex task. This paper address thisissue with a probabilistic identification analysis that combines multiplesadvanced identification techniques and returns an ordered list of probableprotocols. It combines a payload analysis with a classifier based onseveral discriminators, including packet entropy and size. We show withits implementation, that it overcomes the limitations of traditional portbasedprotocol identification when dealing with hard to classify protocolsuch as peer to peer protocols. We also details how it deals with tunneledsession and covert channel.