Network Application Protocol Identification Based on Statistical Methods

徐莉,赵曦,赵群飞,秦涛
DOI: https://doi.org/10.3321/j.issn:0253-987x.2009.02.010
2009-01-01
Abstract:An application protocol identification method is proposed based on the statistical characteristics of network flows.The flow features at the network level are extracted according to the concept of network flow,and three attributes: the number of packets,the number of bytes,and time,are used to capture the flow characteristics roundly.Then the principal component analysis algorithm is used to determine the main characteristics of the flow attributes to reduce the effect of environment.Finally,a BP neural network model is given to identify the application protocols.As the features used in the proposed method are more stable,the output results of the model are hence accurate with the change of the network environment.Experimental results in real network environments show that the proposed method can identify several major application protocols accurately,such as HTTP,BitTorrent,FTP and TELNET,and the identification precision is above 97%.
What problem does this paper attempt to address?