Clear and Present Data: Opaque Traffic and its Security Implications for the Future

نویسندگان

  • Andrew M. White
  • Srinivas Krishnan
  • Michael Bailey
  • Fabian Monrose
  • Phillip A. Porras
چکیده

Opaque traffic, i.e., traffic that is compressed or encrypted, incurs particularly high overhead for deep packet inspection engines and often yields little or no useful information. Our experiments indicate that an astonishing 89% of payload-carrying TCP packets — and 86% of bytes transmitted — are opaque, forcing us to consider the challenges this class of traffic presents for network security, both in the short-term and, as the proportion of opaque traffic continues to rise, for the future. We provide a first step toward addressing some of these challenges by introducing new techniques for accurate real-time winnowing, or filtering, of such traffic based on the intuition that the distribution of byte values found in opaque traffic will differ greatly from that found in transparent traffic. Evaluation on traffic from two campuses reveals that our techniques are able to identify opaque data with 95% accuracy, on average, while examining less than 16 bytes of payload data. We implemented our most promising technique as a preprocessor for the Snort IDS and compared the performance to a stock Snort instance by running both instances live, on identical traffic streams, using a Data Acquisition and Generation (DAG) card deployed within a campus network. Winnowing enabled Snort to handle a peak load of 1.2Gbps, with zero percent packet loss, and process almost one hundred billion packets over 24 hours — a 147% increase over the number processed by the stock Snort instance. This increase in capacity resulted in 33,000 additional alerts which would otherwise have been missed.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Building a Persian Gulf Missile Defense Shield and its Impact on Regional Security: (2001-2017)

The gradual development of the US missile defense shield from Europe to the Persian Gulf region over the past decade and the deployment of radar components and defenses of this project, both in the Persian Gulf region and in its floating zone, have plenty implications for regional and international systems and has aggravated the fragile security of the Persian Gulf region. Some issues such as t...

متن کامل

India's Energy Strategy by 2035 and Its Implications for I. R. of Iran

The energy sector is a most promising area for commercial interactions between Iran and India. India is expected to become the third biggest oil consumer in the World by 2035, thanks to the country’s high population and high rate of economic growth.  On the other hand, Iran holds the world's largest gas reserves and third largest oil reserves, as such is able to meet India’s energy needs for a ...

متن کامل

Millets for Food and Nutrition Security in India: Determinants and Policy Implications

Background: Food security has been a target in India since its independence; the primary aim of food security is to ensure enough staple food for the entire population. Although substantial progress was made through the adoption of green revolution (GR) technologies and implementation of the food public distribution system (PDS), desirable food and nutrition security, as defined by the food and...

متن کامل

An Incentive-Aware Lightweight Secure Data Sharing Scheme for D2D Communication in 5G Cellular Networks

Due to the explosion of smart devices, data traffic over cellular networks has seen an exponential rise in recent years. This increase in mobile data traffic has caused an immediate need for offloading traffic from operators. Device-to-Device(D2D) communication is a promising solution to boost the capacity of cellular networks and alleviate the heavy burden on backhaul links. However, dir...

متن کامل

IFRS or IFRS-Based Domestic Standards: Implications for China’s Future Accounting System

People’s Republic of China has a long history of accounting and accounting reforms. This study focuses on “whether China should continue its IFRS-based domestic accounting standards or full convergence with the IFRS is more appropriate”? Both quantitative and qualitative approaches are applied to answer the research question of this work. Binary choice model has been used in the statistical ana...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013