HEDGE: Efficient Traffic Classification of Encrypted and Compressed Packets

05/28/2019
by   Fran Casino, et al.
0

As the size and source of network traffic increase, so does the challenge of monitoring and analysing network traffic. Therefore, sampling algorithms are often used to alleviate these scalability issues. However, the use of high entropy data streams, through the use of either encryption or compression, further compounds the challenge as current state of the art algorithms cannot accurately and efficiently differentiate between encrypted and compressed packets. In this work, we propose a novel traffic classification method named HEDGE (High Entropy DistinGuishEr) to distinguish between compressed and encrypted traffic. HEDGE is based on the evaluation of the randomness of the data streams and can be applied to individual packets without the need to have access to the entire stream. Findings from the evaluation show that our approach outperforms current state of the art. We also make available our statistically sound dataset, based on known benchmarks, to the wider research community.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/15/2020

EnCoD: Distinguishing Compressed and Encrypted File Fragments

Reliable identification of encrypted file fragments is a requirement for...
research
05/07/2018

Detecting Compressed Cleartext Traffic from Consumer Internet of Things Devices

Data encryption is the primary method of protecting the privacy of consu...
research
06/05/2020

Can the Multi-Incoming Smart Meter Compressed Streams be Re-Compressed?

Smart meters have currently attracted attention because of their high ef...
research
10/19/2021

CGNN: Traffic Classification with Graph Neural Network

Traffic classification associates packet streams with known application ...
research
07/30/2020

Traffic Optimization for TCP-based Massive Multiplayer Online Games

This paper studies the use of a traffic optimization technique named TCM...
research
03/31/2021

Reliable Detection of Compressed and Encrypted Data

Several cybersecurity domains, such as ransomware detection, forensics a...
research
01/24/2021

Encrypted Internet traffic classification using a supervised Spiking Neural Network

Internet traffic recognition is an essential tool for access providers s...

Please sign up or login with your details

Forgot password? Click here to reset