Skip to main navigation Skip to search Skip to main content

Comparison and analysis of flow features at the packet level for traffic classification

  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Recently, flow features at the packet level for traffic classification have been paid more attention to since they are simple and observable even if encrypted tunnels are applied in the network, such as SSL tunnel. However, how to use flow features at the packet level for effective classification of traffic flows is still a significant issue to be solved. The objective of this paper is to compare and analyze three typical flow features at the packet level: packet size combined with packet direction, packet size combined with interarrival time, and protocol fingerprint. The amount of information carried by each feature is presented with mutual information measurement. Based on the traffic traces captured from two different network environments, our experimental results indicate that when C4.5 algorithm classifies traffic flows with the first two packets of each flow, packet size combined with packet interarrival time, which is generated from the client-to-server direction of a TCP connection, is more accurate and stable across space and time.

Original languageEnglish
Title of host publicationProceedings - 2012 International Conference on Connected Vehicles and Expo, ICCVE 2012
Pages262-267
Number of pages6
DOIs
StatePublished - 2012
Externally publishedYes
Event2012 1st International Conference on Connected Vehicles and Expo, ICCVE 2012 - Beijing, China
Duration: 12 Dec 201216 Dec 2012

Publication series

NameProceedings - 2012 International Conference on Connected Vehicles and Expo, ICCVE 2012

Conference

Conference2012 1st International Conference on Connected Vehicles and Expo, ICCVE 2012
Country/TerritoryChina
CityBeijing
Period12/12/1216/12/12

Keywords

  • flow features
  • packet level
  • traffic classification

Fingerprint

Dive into the research topics of 'Comparison and analysis of flow features at the packet level for traffic classification'. Together they form a unique fingerprint.

Cite this