作者
Laurent Bernaille, Renata Teixeira
发表日期
2007/4/5
图书
International Conference on Passive and Active Network Measurement
页码范围
165-175
出版商
Springer Berlin Heidelberg
简介
Most tools to recognize the application associated with network connections use well-known signatures as basis for their classification. This approach is very effective in enterprise and campus networks to pinpoint forbidden applications (peer to peer, for instance) or security threats. However, it is easy to use encryption to evade these mechanisms. In particular, Secure Sockets Layer (SSL) libraries such as OpenSSL are widely available and can easily be used to encrypt any type of traffic. In this paper, we propose a method to detect applications in SSL encrypted connections. Our method uses only the size of the first few packets of an SSL connection to recognize the application, which enables an early classification. We test our method on packet traces collected on two campus networks and on manually-encrypted traces. Our results show that we are able to recognize the application in an SSL connection …
引用总数
200620072008200920102011201220132014201520162017201820192020202120222023202418112218232021161319212113221824172
学术搜索中的文章
L Bernaille, R Teixeira - International Conference on Passive and Active …, 2007