Detecting Peer-to-Peer Activity by Signaling Packet Counting ∗
Chen‐Chi Wu, Kuan-Ta Chen, Yuchun Chang, Chin‐Laung Lei · 2008
Managing peer-to-peer traffic is a major challenge for network administrators, because peer-to-peer applications tend to use dynamic port numbers and proprietary protocols. In view of this problem, we propose an approach that combines the advantages of payload-based and transport-layer approaches, and avoids their disadvantages. Specifically, our approach can recognize particular peer-to-peer applications running on the monitored host without checking packet payloads. The experiment results show that our scheme can successfully recognize the traffic from BitTorrent, eMule, or Skype with 98 % correct rate within 6 minutes and 99 % correct rate within 15 minutes.