Skip to main navigation Skip to search Skip to main content

Automatically mining application signatures for lightweight deep packet inspection

  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Automatic signature generation approaches have been widely applied in recent traffic classification. However, they are not suitable for LightWeight Deep Packet Inspection (LW-DPI) since their generated signatures are matched through a search of the entire application data. On the basis of LW-DPI schemes, we present two Hierarchical Clustering (HC) algorithms: HC-TCP and HC-UDP, which can generate byte signatures from TCP and UDP packet payloads respectively. In particular, HC-TCP and HC-UDP can extract the positions of byte signatures in packet payloads. Further, in order to deal with the case in which byte signatures cannot be derived, we develop an algorithm for generating bit signatures. Compared with the LASER algorithm and Suffix Tree (ST)-based algorithm, the proposed algorithms are better in terms of both classification accuracy and speed. Moreover, the experimental results indicate that, as long as the application-protocol header exists, it is possible to automatically derive reliable and accurate signatures combined with their positions in packet payloads.

Original languageEnglish
Article number06549262
Pages (from-to)86-99
Number of pages14
JournalChina Communications
Volume10
Issue number6
DOIs
StatePublished - Jun 2013
Externally publishedYes

Keywords

  • Association mining
  • Automatic signature generation
  • Hierarchical clustering
  • LW-DPI
  • Traffic classification

Fingerprint

Dive into the research topics of 'Automatically mining application signatures for lightweight deep packet inspection'. Together they form a unique fingerprint.

Cite this