Identifying the Use of Data/Voice/Video-Based P2P Traffic by DNS-Query Behavior
Hung-Shen Wu, Nen-Fu Huang, G.-H. Lin · 2009
There are more and more P2P applications in the Internet, with or without encrypted content. The P2P applications can be classified into three categories: file sharing (BT, eMule), VoIP (Skype, MSN), and video streaming (PPStream, PPLive). By observing the common communication nature among the peers, this paper proposes a simple but efficient way to identify the P2P traffic by the DNS query behavior. Experimental results illustrate that the proposed mechanism is able to accurately identify if a host is using data/voice/video-based P2P traffic, even the packet content is encrypted. The proposed mechanism is also capable of detecting future unknown P2P applications as long as they perform the common P2P behaviors.