Identification of P2P Flow Based on Node and Traffic Behavior Characteristics
Shan Ka · Journal of University of Jinan · 2014
The current P2P software uses dynamic ports and load encryption technology widely so that it limits peer-to-peer network traffic identification,which is based on the transport layer port and deep packet inspection( DPI) technology. Through the P2P traffic analysis,it is found that P2P node has double characteristics: firstly,P2P nodes can upload and also download the data,which means the nodes have duality; secondly,the variance ratio of forward and reverse flow package of time interval fluctuates within a certain range. Thus a P2P traffic identification method based on nodes and flow behavior characteristics is proposed and applied to network traffic monitoring. The results show that this method can objectively identify new applications and encrypted traffic with 93% flow identification rate and 95. 5% byte identification rate.