Title of Thesis: Improving Packet Classification: Learning from Traffic Improving Packet Classification: Learning from Traffic

نویسندگان

  • Kevin Lyle Andrusky
  • Chintha Tellambura
  • Martin Müller
چکیده

Some rules in a packet classifier’s ruleset are more likely to be matched than others. Which of these rules are most likely to be matched cannot be known a priori, however. As a result, a classifier should be able to adapt itself to the traffic that it sees. This thesis explores the idea of using the traffic a packet classifier is seeing to tune that classifier’s search structure in order to improve its average response time. To test this idea, HICuts, a heuristic-based packet classifier recently proposed by Gupta and McKeown, was modified to periodically restructure itself to best match the traffic it is seeing. In addition, a Ternary Content Addressable Memory (TCAM) was added to the classifier to act as a form of transposition table. The classifier was also given the ability to maintain a worst-case bound on its performance, as, by the nature of Internet traffic, classifiers must ensure that all possible packets be matched in a reasonable amount of time. In order to describe the effects of restructuring, several modifications were made to an Interval Decision Diagram (IDD) notation. Such notation can be used as a HICuts tree is essentially an IDD tree with a slightly different condition for creating leaf nodes. Experimental results drawn from synthetic tests designed to test specific situations and extreme cases, and from real-world tests using actual packet traces are shown. In experimentation, compared to the original static HICuts classifier, the new dynamic classifier performed significantly better in terms of the amount of work performed during classification, while maintaining a strict bound on its worst-case performance.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Feature Extraction to Identify Network Traffic with Considering Packet Loss Effects

There are huge petitions of network traffic coming from various applications on Internet. In dealing with this volume of network traffic, network management plays a crucial rule. Traffic classification is a basic technique which is used by Internet service providers (ISP) to manage network resources and to guarantee Internet security. In addition, growing bandwidth usage, at one hand, and limit...

متن کامل

Behavioral Analysis of Traffic Flow for an Effective Network Traffic Identification

Fast and accurate network traffic identification is becoming essential for network management, high quality of service control and early detection of network traffic abnormalities. Techniques based on statistical features of packet flows have recently become popular for network classification due to the limitations of traditional port and payload based methods. In this paper, we propose a metho...

متن کامل

Exploiting Adaptive Packet-Sampling Measurements for Multimedia Traffic Classification

Abstract—With the huge amount of ubiquitous multimedia data transmitted in nowadays Internet, the use of packet sampling for traffic measurements has become widely employed for network operators. In this paper, we present an adaptive packet sampling technique from the classification perspective, the main sampling principle of which is to select as many packets with low occurrence rate as possi...

متن کامل

An SVM-based machine learning method for accurate internet traffic classification

Accurate and timely traffic classification is critical in network security monitoring and traffic engineering. Traditional methods based on port numbers and protocols have proven to be ineffective in terms of dynamic port allocation and packet encapsulation. The signature matching methods, on the other hand, require a known signature set and processing of packet payload, can only handle the sig...

متن کامل

Classification of encrypted traffic for applications based on statistical features

Traffic classification plays an important role in many aspects of network management such as identifying type of the transferred data, detection of malware applications, applying policies to restrict network accesses and so on. Basic methods in this field were using some obvious traffic features like port number and protocol type to classify the traffic type. However, recent changes in applicat...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005