An Novel Hybrid Method for Effectively Classifying Encrypted Traffic

作者:Sun Guang Lu*; Xue Yibo; Dong Yingfei; Wang Dongsheng; Li Chenglong
来源:IEEE Global Telecommunications Conference (GLOBECOM 2010), 2010-12-06 To 2010-12-10.
DOI:10.1109/glocom.2010.5683649

摘要

Classifying encrypted traffic is critical to effective network analysis and management. While traditional payload-based methods are powerless to deal with encrypted traffic, machine learning methods have been proposed to address this issue. However, these methods often bring heavy overhead into the system. In this paper, we propose a hybrid method that combines signature-based methods and statistical analysis methods to address this issue. We first identify SSL/TLS traffic with signature matching methods, and then apply statistical analysis to determine concrete application protocols. Our experimental results show that the proposed method is able to recognize over 99% of SSL/TLS traffic and achieve 94.52% in F-score for protocols identification.