A New P2P Traffic Identification Model Based on Node Status

Xuanmin Lu, Pei Jiang, Yajian Zhou · 2010

Random port, blurred protocol features, as well as HTTP tunneling technology have become more and more popular in the new P2P applications. It makes current P2P traffic identification methods based on traffic features or deep packet inspection increasingly ineffective. To resolve this problem, a new P2P traffic identification model based on node's status is proposed in this paper. Through multi-level identification modules, the obtained node's status is stored into a Hash table, and a trusted list is created by mapping and feedback to the end of identification. Moreover, the definition of the active factor, incremental factor and link cache can help to identify the P2P traffic generated by port hopping and protocol encryption quickly and effectively.

Read the paper · More papers on PaperTik