论文标题

早期识别HTTPS流量中的服务

Early Identification of Services in HTTPS Traffic

论文作者

Shbair, Wazen M., Cholez, Thibault, Francois, Jerome, Chrisment, Isabelle

论文摘要

流量监视对于确保安全性和QoS的网络管理任务至关重要。但是,HTTPS流量的持续增加破坏了当前服务级监视的有效性,这些监视只能依靠TLS握手(X.509证书,SNI)或必须解密流量的不可靠参数。我们提出了一种基于机器学习的新方法,以识别HTTPS服务而无需解密。通过在TLS握手数据包上提取统计功能以及少量的应用程序数据包上的统计功能,我们可以在会话早期很早就识别HTTPS服务。在一个重要且开放的数据集中进行的广泛实验表明,我们的方法具有良好的准确性,并且原型实现证实了对HTTPS服务的早期识别。

Traffic monitoring is essential for network management tasks that ensure security and QoS. However, the continuous increase of HTTPS traffic undermines the effectiveness of current service-level monitoring that can only rely on unreliable parameters from the TLS handshake (X.509 certificate, SNI) or must decrypt the traffic. We propose a new machine learning-based method to identify HTTPS services without decryption. By extracting statistical features on TLS handshake packets and on a small number of application data packets, we can identify HTTPS services very early in the session. Extensive experiments performed over a significant and open dataset show that our method offers a good accuracy and a prototype implementation confirms that the early identification of HTTPS services is satisfied.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源