Presentation 2005-12-15
Application Classification Method based on Flow Behavior Analysis
Tsutomu KITAMURA, Takayuki SHIZUNO, Toshiya OKABE,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) Existing gateway equipments such as session border controller (SBC) or firewall gateway identify and control application packet flows by analyzing packet headers and payloads - such as TCP/UDP port numbers and specific bit strings. However this approach is not effective under the following conditions, where 1) applications use intentionally well-known ports with improper use, 2) the payloads are encrypted. We have developed an application classification method based on analyzing flow behaviors - such as packet size, inter-arrival time between packets. We evaluated the proposed method in application classification performance. The results show that the proposed method can work in the above conditions.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) Flow Behavior / Application Classification
Paper # NS2005-136
Date of Issue

Conference Information
Committee NS
Conference Date 2005/12/8(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Network Systems(NS)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Application Classification Method based on Flow Behavior Analysis
Sub Title (in English)
Keyword(1) Flow Behavior
Keyword(2) Application Classification
1st Author's Name Tsutomu KITAMURA
1st Author's Affiliation NEC Corporation()
2nd Author's Name Takayuki SHIZUNO
2nd Author's Affiliation NEC Corporation
3rd Author's Name Toshiya OKABE
3rd Author's Affiliation NEC Corporation
Date 2005-12-15
Paper # NS2005-136
Volume (vol) vol.105
Number (no) 470
Page pp.pp.-
#Pages 4
Date of Issue