Lightweight Internet Traffic Classification based on Packet Level Hidden Markov Models
نویسنده
چکیده
During the last decade, Internet traffic classification finds its importance not only to safeguard the integrity and security of network resources, but also to ensure the quality of service for business critical applications by optimizing existing network resources. But optimization at first place requires correct identification of different traffic flows. In this paper, we have suggested a framework based on Hidden Markov Model, which will use Internet Packet intrinsic statistical characteristics for traffic classification. The packet inspection based on statistical analysis of its different characteristics has helped to reduce overall computational complexity. Generally, the major challenges associated with any internet traffic classifier are: 1) the limitation to accurately identify encrypted traffic when classification is performed using traditional port based techniques; 2) overall computational complexity, and 3 ) to achieve high accuracy in traffic identification. Our methodology takes advantage of internet packet statistical characteristics in terms of its size and their inter arrival time in order to model different traffic flows. For experimental results, the data set of mostly used internet applications was used. The proposed HMM models best fit the observed traffic with high accuracy. Achieved traffic identification accuracy was 91% for packet size classifier whereas it was 82% for inter packet time based classifier. Keywords—Hidden Markov model; traffic classification; network security; deep packet inspection; internet traffic modeling; Internet of Things
منابع مشابه
Feature Extraction to Identify Network Traffic with Considering Packet Loss Effects
There are huge petitions of network traffic coming from various applications on Internet. In dealing with this volume of network traffic, network management plays a crucial rule. Traffic classification is a basic technique which is used by Internet service providers (ISP) to manage network resources and to guarantee Internet security. In addition, growing bandwidth usage, at one hand, and limit...
متن کاملInternet traffic modeling by means of Hidden Markov Models
In this work, we propose a Hidden Markov Model for Internet traffic sources at packet level, jointly analyzing Inter Packet Time and Packet Size. We give an analytical basis and the mathematical details regarding the model, and we test the flexibility of the proposed modeling approach with real traffic traces related to common Internet services with strong differences in terms of both applicati...
متن کاملAn HMM Approach to Internet Traffic Modeling
Traffic modeling is a fertile research area. This paper proposes a packet-level traffic model of traffic sources based on Hidden Markov Model. It has been developed by using real network traffic and estimating in a combined fashion Packet Size and Inter Packet Time. The effectiveness of the proposed model is evaluated by studying several traffic types with strong differences in terms of both ap...
متن کاملEntropy-Based Characterization of Internet Background Radiation
Network security requires real-time monitoring of network traffic in order to detect new and unexpected attacks. Attack detection methods based on deep packet inspection are time consuming and costly, due to their high computational demands. This paper proposes a fast, lightweight method to distinguish different attack types observed in an IP darkspace monitor. The method is based on entropy me...
متن کاملModeling of multiplexed video streams in IP networks
In the recent years, it has been shown that the behavior of variable bit rate (VBR) video sources cannot be captured by the traditional Markov models since they do not exhibit a long-range dependent (LRD) characteristic which on the contrary is present in video traffic. Since then, a debate has been opened to understand the actual behavior of packet sources and the influence of this fact onto n...
متن کامل