Tunneling protocols identification using light packet inspection

K. Kazemi,A. Fanian
DOI: https://doi.org/10.1109/ISCISC.2015.7387907
2015-09-01
Abstract:Network traffic identification is an essential component for effective network analysis and management. Deep Packet Inspection is one of the main methods for traffic identification. DPI methods have high processing cost and require sufficient memory and CPU resources, which lead to the low efficiency. Furthermore, these methods search payload of the packets which may raise the privacy concern of the network users. In this paper we propose an approach for network tunneling protocols identification which is called Light Packet Inspection that overcomes the weaknesses of traditional DPI methods. We introduce major tunneling protocols such as IPsec, PPTP and OpenVPN communication mechanism in detail, and give an analysis of their packets and traffic behaviors. The experiment results show that the proposed approach can identify tunnels in the early period of time with high accuracy and low processing cost.
What problem does this paper attempt to address?