Protocol Independent Identification of Encrypted Traffic Based on Weighted Cumulative Sum Test

ZHAO Bo,GUO Hong,LIU Qin-Rang,WU Jiang-Xing
DOI: https://doi.org/10.3724/sp.j.1001.2013.04279
2014-01-01
Journal of Software
Abstract:A protocol independent identification algorithm is proposed to identify encrypted traffic from both public and private encryption protocols. The randomness of the packet is evaluated by a cumulative test. In addition, results are weighted conflated. A test is performed when every new packet arrived rather than after all packets have received, so that time consumed computation is avoided. The quantity of packets may vary dynamically according to delay and accuracy requirement. Experiments results show that the algorithm achieves accuracy above 90%for SSL and private encryption protocol traffic.
What problem does this paper attempt to address?