TY - GEN
T1 - TCP traffic classification using Markov models
AU - Münz, Gerhard
AU - Dai, Hui
AU - Braun, Lothar
AU - Carle, Georg
PY - 2010
Y1 - 2010
N2 - This paper presents a novel traffic classification approach which classifies TCP connections with help of observable Markov models. As traffic properties, payload length, direction, and position of the first packets of a TCP connection are considered. We evaluate the accuracy of the classification approach with help of packet traces captured in a real network, achieving higher accuracies than the cluster-based classification approach of Bernaille [1]. As another advantage, the complexity of the proposed Markov classifier is low for both training and classification. Furthermore, the classification approach provides a certain level of robustness against changed usage of applications.
AB - This paper presents a novel traffic classification approach which classifies TCP connections with help of observable Markov models. As traffic properties, payload length, direction, and position of the first packets of a TCP connection are considered. We evaluate the accuracy of the classification approach with help of packet traces captured in a real network, achieving higher accuracies than the cluster-based classification approach of Bernaille [1]. As another advantage, the complexity of the proposed Markov classifier is low for both training and classification. Furthermore, the classification approach provides a certain level of robustness against changed usage of applications.
UR - https://www.scopus.com/pages/publications/77952048799
U2 - 10.1007/978-3-642-12365-8_10
DO - 10.1007/978-3-642-12365-8_10
M3 - Conference contribution
AN - SCOPUS:77952048799
SN - 3642123643
SN - 9783642123641
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 127
EP - 140
BT - Traffic Monitoring and Analysis - Second International Workshop, TMA 2010, Proceedings
T2 - 2nd International Workshop on Traffic Monitoring and Analysis, TMA 2010
Y2 - 7 April 2010 through 7 April 2010
ER -