Classification of Encrypted Network Traffic
摘要
The central activity of many crucial network monitoring and supervisory operations, such as quality of service, billing and anomaly detection is the classification of network flows based on application. A serious challenge in traffic analysis is to extract effective and reliable features. In this chapter, we will discuss the traffic classification based on port-based, flow-based and packet-based features which are widely used in literature. In addition, traffic can be categorised according to the final purpose, such as traffic with encryption (e.g. encrypted traffic), encapsulating protocol (e.g. tunnelled Virtual Private Network (VPN) or HyperText Transfer Protocol Secure (HTTPS)); according to application specific like Skype or according to the application category like chat, video streaming, etc. In this chapter, we discuss the effect of packet header, time-based attributes, single-flow and multiple-flow attributes for encrypted traffic classification. We also review these attributes in different types of applications like Secure Shell (SSH), VPN, TOR, Advanced Metering Infrastructure (AMI) to characterise the encrypted traffic with high accuracy and performance.