<p>Operating system (OS) detection through NetFlow data has been a well-explored area, primarily focusing on more features in the application layer or the transport layer such as TCP and UDP. However, there is a notable dearth of research activities concerning the utilization of basic NetFlow attributes, such as source address and source port, for OS type detection. This gap can be attributed to the perception that these features lack direct associations with OS types and may be vulnerable to deception in network environments. In this paper, we set out to explore the accessibility, rather than the effectiveness, of employing these fundamental NetFlow traffic features for OS type detection and potentially improving detection performance. Specifically, we hypothesize that metrics such as those of link amount, TCP port usage patterns, and connection duration may reveal valuable associations with OS types, offering a novel approach to OS detection. Our primary objective is to investigate the validity of this hypothesis and contribute to the development of accessible OS type detection methodologies. Through rigorous experimentation and analysis, we aim to shed light on the potential of these underexplored NetFlow attributes as indicators of OS types. Our experimental results exhibit robustness compared to similar researches. Additionally, these results achieve an 8% improvement in balanced accuracy compared to traditional methods, while preserving its cost-effectiveness. This improvement is of significant importance, especially in scenarios where the parameters of different OS types closely resemble each other, posing a challenge for traditional feature-based approaches.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Netflow-based operating system identification using machine learning

  • Kun-Lin Hsieh,
  • Ting-Xiao Miaw,
  • Quincy Wu,
  • Meng-Shuo Shen

摘要

Operating system (OS) detection through NetFlow data has been a well-explored area, primarily focusing on more features in the application layer or the transport layer such as TCP and UDP. However, there is a notable dearth of research activities concerning the utilization of basic NetFlow attributes, such as source address and source port, for OS type detection. This gap can be attributed to the perception that these features lack direct associations with OS types and may be vulnerable to deception in network environments. In this paper, we set out to explore the accessibility, rather than the effectiveness, of employing these fundamental NetFlow traffic features for OS type detection and potentially improving detection performance. Specifically, we hypothesize that metrics such as those of link amount, TCP port usage patterns, and connection duration may reveal valuable associations with OS types, offering a novel approach to OS detection. Our primary objective is to investigate the validity of this hypothesis and contribute to the development of accessible OS type detection methodologies. Through rigorous experimentation and analysis, we aim to shed light on the potential of these underexplored NetFlow attributes as indicators of OS types. Our experimental results exhibit robustness compared to similar researches. Additionally, these results achieve an 8% improvement in balanced accuracy compared to traditional methods, while preserving its cost-effectiveness. This improvement is of significant importance, especially in scenarios where the parameters of different OS types closely resemble each other, posing a challenge for traditional feature-based approaches.