Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Network traffic classification : from theory to practice

View through CrossRef
Since its inception until today, the Internet has been in constant transformation. The analysis and monitoring of data networks try to shed some light on this huge black box of interconnected computers. In particular, the classification of the network traffic has become crucial for understanding the Internet. During the last years, the research community has proposed many solutions to accurately identify and classify the network traffic. However, the continuous evolution of Internet applications and their techniques to avoid detection make their identification a very challenging task, which is far from being completely solved. This thesis addresses the network traffic classification problem from a more practical point of view, filling the gap between the real-world requirements from the network industry, and the research carried out. The first block of this thesis aims to facilitate the deployment of existing techniques in production networks. To achieve this goal, we study the viability of using NetFlow as input in our classification technique, a monitoring protocol already implemented in most routers. Since the application of packet sampling has become almost mandatory in large networks, we also study its impact on the classification and propose a method to improve the accuracy in this scenario. Our results show that it is possible to achieve high accuracy with both sampled and unsampled NetFlow data, despite the limited information provided by NetFlow. Once the classification solution is deployed it is important to maintain its accuracy over time. Current network traffic classification techniques have to be regularly updated to adapt them to traffic changes. The second block of this thesis focuses on this issue with the goal of automatically maintaining the classification solution without human intervention. Using the knowledge of the first block, we propose a classification solution that combines several techniques only using Sampled NetFlow as input for the classification. Then, we show that classification models suffer from temporal and spatial obsolescence and, therefore, we design an autonomic retraining system that is able to automatically update the models and keep the classifier accurate along time. Going one step further, we introduce next the use of stream-based Machine Learning techniques for network traffic classification. In particular, we propose a classification solution based on Hoeffding Adaptive Trees. Apart from the features of stream-based techniques (i.e., process an instance at a time and inspect it only once, with a predefined amount of memory and a bounded amount of time), our technique is able to automatically adapt to the changes in the traffic by using only NetFlow data as input for the classification. The third block of this thesis aims to be a first step towards the impartial validation of state-of-the-art classification techniques. The wide range of techniques, datasets, and ground-truth generators make the comparison of different traffic classifiers a very difficult task. To achieve this goal we evaluate the reliability of different Deep Packet Inspection-based techniques (DPI) commonly used in the literature for ground-truth generation. The results we obtain show that some well-known DPI techniques present several limitations that make them not recommendable as a ground-truth generator in their current state. In addition, we publish some of the datasets used in our evaluations to address the lack of publicly available datasets and make the comparison and validation of existing techniques easier.
Universitat Politècnica de Catalunya
Title: Network traffic classification : from theory to practice
Description:
Since its inception until today, the Internet has been in constant transformation.
The analysis and monitoring of data networks try to shed some light on this huge black box of interconnected computers.
In particular, the classification of the network traffic has become crucial for understanding the Internet.
During the last years, the research community has proposed many solutions to accurately identify and classify the network traffic.
However, the continuous evolution of Internet applications and their techniques to avoid detection make their identification a very challenging task, which is far from being completely solved.
This thesis addresses the network traffic classification problem from a more practical point of view, filling the gap between the real-world requirements from the network industry, and the research carried out.
The first block of this thesis aims to facilitate the deployment of existing techniques in production networks.
To achieve this goal, we study the viability of using NetFlow as input in our classification technique, a monitoring protocol already implemented in most routers.
Since the application of packet sampling has become almost mandatory in large networks, we also study its impact on the classification and propose a method to improve the accuracy in this scenario.
Our results show that it is possible to achieve high accuracy with both sampled and unsampled NetFlow data, despite the limited information provided by NetFlow.
Once the classification solution is deployed it is important to maintain its accuracy over time.
Current network traffic classification techniques have to be regularly updated to adapt them to traffic changes.
The second block of this thesis focuses on this issue with the goal of automatically maintaining the classification solution without human intervention.
Using the knowledge of the first block, we propose a classification solution that combines several techniques only using Sampled NetFlow as input for the classification.
Then, we show that classification models suffer from temporal and spatial obsolescence and, therefore, we design an autonomic retraining system that is able to automatically update the models and keep the classifier accurate along time.
Going one step further, we introduce next the use of stream-based Machine Learning techniques for network traffic classification.
In particular, we propose a classification solution based on Hoeffding Adaptive Trees.
Apart from the features of stream-based techniques (i.
e.
, process an instance at a time and inspect it only once, with a predefined amount of memory and a bounded amount of time), our technique is able to automatically adapt to the changes in the traffic by using only NetFlow data as input for the classification.
The third block of this thesis aims to be a first step towards the impartial validation of state-of-the-art classification techniques.
The wide range of techniques, datasets, and ground-truth generators make the comparison of different traffic classifiers a very difficult task.
To achieve this goal we evaluate the reliability of different Deep Packet Inspection-based techniques (DPI) commonly used in the literature for ground-truth generation.
The results we obtain show that some well-known DPI techniques present several limitations that make them not recommendable as a ground-truth generator in their current state.
In addition, we publish some of the datasets used in our evaluations to address the lack of publicly available datasets and make the comparison and validation of existing techniques easier.

Related Results

The Burden of Road Traffic Injuries: A Global Perspective
The Burden of Road Traffic Injuries: A Global Perspective
Introduction     Road Traffic Injury (RTI) pose a significant health challenge. It represents the eighth leading cause of death globally, prompting the UN to designate 2011-2020 as...
Introduction to Artificial Intelligence in Traffic Systems
Introduction to Artificial Intelligence in Traffic Systems
Traffic management is a pressing challenge in modern societies. The population of humans is increasing at a substantial pace, and along with that, the expanse of urban areas and th...
Traffic Prediction in 5G Networks Using Machine Learning
Traffic Prediction in 5G Networks Using Machine Learning
The advent of 5G technology promises a paradigm shift in the realm of telecommunications, offering unprecedented speeds and connectivity. However, the ...
Network Traffic Prediction Based on Boosting Learning
Network Traffic Prediction Based on Boosting Learning
Classification of network traffic is an important topic for network management, traffic routing, safe traffic discrimination, and better service delivery. Traffic examination is th...
Smart Traffic Control Using Computer Vision
Smart Traffic Control Using Computer Vision
A Smart Traffic Control System using Computer Vision utilizes cameras, image processing techniques, and machine learning algorithms to monitor, analyze, and manage traffic flow aut...
TYPES OF AI ALGORİTHMS USED İN TRAFFİC FLOW PREDİCTİON
TYPES OF AI ALGORİTHMS USED İN TRAFFİC FLOW PREDİCTİON
The increasing complexity of urban transportation systems and the growing volume of vehicles have made traffic congestion a persistent challenge in modern cities. Efficient traffic...
Traffic safety outcomes of traffic law application and the adoption of new technology in traffic control
Traffic safety outcomes of traffic law application and the adoption of new technology in traffic control
Experience of the State of Qatar Introduction: Since the second half of the last decade of the twentieth century, Qatar has witnessed the implementation of a comprehensive developm...

Back to Top