Traffic classification on the fly

Laurent Bernaille, Renata Teixeira, Ismael Akodkenou, Augustin Soule, Kavé Salamatian · ACM SIGCOMM Computer Communication Review · 2006

The early detection of applications associated with TCP flows is an essential step for network security and traffic engineering. The classic way to identify flows, i.e. looking at port numbers, is not effective anymore. On the other hand, state-of-the-art techniques cannot determine the application before the end of the TCP flow. In this editorial, we propose a technique that relies on the observation of the first five packets of a TCP connection to identify the application. This result opens a range of new possibilities for online traffic classification.

Read the paper · More papers on PaperTik