Associating network flows with user and application information

Ralf Ackermann, Utz Roedig, Michael Zink, Carsten Griwodz, Ralf Steinmetz · 2000

The concept of authenticating users e.g. by means of a login process is very well established and there is no doubt that it is absolutely necessary and helpful in a multiuser environment. Unfortunately specific information about a user originating a data stream or receiving it, is often no longer available at the traversed network nodes. This applies to the even more specific question of what application is used as well. Routers, gateways or firewalls usually have to base their classification of data on IP header inspection or have to try to extract information from the packets payload.

Read the paper · More papers on PaperTik