earticle

논문검색

The Effectiveness Study of ML-based Methods for Protocol Identification in Different Network Environments

초록

영어

Due to the wide use of encrypted protocols and random ports, traditional methods that based on port number or packet payload have gradually lose their effectiveness. To address this issue, new methods that based on machine learning techniques become the research hotspots. With many further studies, some research institutions show that ML-based protocol identification methods can generally achieve over 95% accuracy. However, different from most research studies, industry claims that ML-based techniques are hardly to be deployed for practical use due to their high false positives and false negatives. In this paper, different Machine Learning techniques are evaluated for the actual accuracy under different network environments, and a variety of features are tested on different encrypted protocols. The results show that the identification accuracy will go down due to the changed network scale and network environment while the same ML-based models are used under different network environments, and the choices among different Machine Learning techniques, protocol types or statistical features are not critical.

목차

Abstract
 1. Introduction
 2. Relate Work
 3. Experimental Method
  3.1. Data Sources and Protocol Categories
  3.2. Algorithms and Feature Selection
  3.3. Evaluation Criteria
 4. Results and Analysis
  4.1. Experiment 1: Accuracy in the Same Data Set
  4.2. Experiment 2: Accuracy in Different Data Sets
  4.3. Analysis of Experimental Results
 5. Conclusion
 Acknowledgements
 References

저자정보

  • Zhang Luoshi School of Computer Science and Technology, Harbin University of Science and Technology, Harbin 150080, China
  • Xue Yibo Research Inst. of Info. & Tech., Tsinghua University, Beijing 100084, China
  • Wang Dawei National Computer Network Emergency Response Technical Team / Coordination Center of China (CNCERT/CC), Beijing, 100029, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.