Using a behaviour knowledge space approach for detecting unknown IP traffic flows

  • Authors:
  • Alberto Dainotti;Antonio Pescapé;Carlo Sansone;Antonio Quintavalle

  • Affiliations:
  • Department of Computer Engineering and Systems, Universitá di Napoli Federico II;Department of Computer Engineering and Systems, Universitá di Napoli Federico II;Department of Computer Engineering and Systems, Universitá di Napoli Federico II;Department of Computer Engineering and Systems, Universitá di Napoli Federico II

  • Venue:
  • MCS'11 Proceedings of the 10th international conference on Multiple classifier systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

The assignment of an IP flow to a class, according to the application that generated it, is at the basis of any modern network management platform. In several network scenarios, however, it is quite unrealistic to assume that all the classes an IP flow can belong to are a priori known. In these cases, in fact, some network protocols may be known, but novel protocols can appear so giving rise to unknown classes. In this paper, we propose to face the problem of classifying IP flows by means of a multiple classifier approach based on the Behaviour Knowledge Space (BKS) combiner. It has been explicitly devised in order to effectively address the problem of the unknown traffic too. To demonstrate the effectiveness of the proposed approach we present an experimental evaluation on a real traffic trace.