To solve the problems of coarse-grained network traffic fingerprints and large memory consumption in the matching phase
we proposed a fine-grained network traffic classification architecture to achieve automated signature generation and optimize memory. As some portion of the data payload in a function is invariant and the signature reflecting the application function is atypical in internet traffic
the signature generation is mapped into the problem of obtaining the frequently occurring substrings and their corresponding occurrence frequency. In the case of online matching
according to the idea of k-means classification
the distance is redefined and the rules are reorganized using the heuristic heterogeneous bit-split deterministic finite automaton method to achieve the purpose of optimizing memory usage. The experimental results show that without knowing the format of the network traffic protocol
the method can automatically generate fine-grained traffic fingerprints with an average recognition accuracy of 93.65%
and is not sensitive to noise. In addition
if all fingerprint character fragments are re-optimized during matching
when the number of fingerprint rules is above 4 000
it can save nearly 50% of memory requirements compared with the previous bit-split string matching methods.
关键词
Keywords
references
ERMAN J, MAHANTI A, ARLITT M. QRP05-4: internet traffic identification using machine learning [C]∥Proceedings of the IEEE 2016 Global Telecommunications Conference. Piscataway, NJ, USA: IEEE, 2006: 1-6.
WILLIAMS N, ZANDER S, ARMITAGE G. A preliminary performance comparison of five machine learning algorithms for practical IP traffic flow classification [J]. ACM SIGCOMM Computer Communication Review, 2006, 36(5): 5-16.
YOON S H, PARK J S, KIM M S. Behavior signature for fine-grained traffic identification [J]. Applied Mathematics Information Sciences, 2015, 9(2): 523-534.
XIONG Gang, MENG Jiao, CAO Zigang, et al. Research progress and prospects of network traffic classification [J]. Journal of Integration Technology, 2012(1): 32-42.
BOYER R S, MOORE J S. A fast string searching algorithm [J]. Communications of the ACM, 1977, 20(10): 762-772.
ABDULLAH A, NAZIR A, SENAPAN M, et al. Fast multi-keyword range search using GPGPU [J]. GPU Computing and Applications, 2015: 259-274.
SOURDIS I, PNEVMATIKATOS D N, VASSILIADIS S. Scalable multigigabit pattern matching for packet inspection [J]. IEEE Transactions on Very Large Scale Integration(VLSI)Systems, 2008, 16(2): 156-166.
XU Kefu, QI Deyu, QIAN Zhengping, et al. Fast dynamic pattern matching for deep packet inspection [C]∥Proceedings of the 2008 IEEE International Conference on Networking, Sensing and Control. Piscataway, NJ, USA: IEEE, 2008: 802-807.
KIM H, KANG S. A pattern group partitioning for parallel string matching using a pattern grouping metric [J]. IEEE Communications Letters, 2010, 14(9): 878-880.
KIM H, CHOI K I, CHOI S I. A memory-efficient deterministic finite automaton-based bit-split string matching scheme using pattern uniqueness in deep packet inspection [J]. PLoS One, 2015, 10(5): e0126517.
AHO A V, CORASICK M J. Efficient string matching: an aid to bibliographic search [J]. Communications of the ACM, 1975, 18(6): 333-340.
LE H, PRASANNA V K. A memory-efficient and modular approach for large-scale string pattern matching [J]. IEEE Transactions on Computers, 2013, 62(5): 844-857.
HUA N, SONG H, LAKSHMAN T V. Variable-stride multi-pattern matching for scalable deep packet inspection [C]∥Proceedings of the 28th IEEE Conference on Computer Communications. Piscataway, NJ, USA: IEEE, 2009: 415-423.
PAO D, LIN W, LIU B. A memory-efficient pipelined implementation of the Aho-Corasick string-matching algorithm [J]. ACM Transactions on Architecture and Code Optimization, 2010, 7(2): 1-27.
YUN S. An efficient TCAM-based implementation of multipattern matching using covered state encoding [J]. IEEE Transactions on Computers, 2012, 61(2): 213-221.
TAN L, BROTHERTON B, SHERWOOD T. Bit-split string-matching engines for intrusion detection and prevention [J]. ACM Transactions on Architecture and Code Optimization, 2006, 3(1): 3-34.
AHO A V. Compilers: principles techniques and tools [M]. 2nd ed. New York, USA: Pearson Education Inc., 2006: 82-101.