Clustering TLS Sessions Based on Protocol Fields Analysis
Hiroaki Yamauchi, Akihiro Nakao, Masato Oguchi, Shu Yamamoto, Saneyasu Yamaguchi · 2018
Many services, such as email, video sharing, and social networking service (SNS), are provided on the Internet. Service identification from given flows is important for various purposes. For example, a severe congestion occurs in disasters and priority control is required for transmitting important information, such as requests for rescues, in that case. Identification of the service of a traffic in network elements achieves this control. The most simple way to identify is that based on IP addresses and port numbers. However, the accuracy of this way is not sufficient. A method for identifying service based on analyzing multiple TSL sessions without using IP addresses and port numbers was proposed. This method clusters TLS sessions according to the 2-gram frequencies of unencrypted parts, which are the fields in handshake messages transmitted at session establishing. However, the existing work did not discuss the effect of each field of the TLS protocol. In this paper, we analyze the ability to cluster of each field. We investigate the ability to cluster sessions of all the unencrypted fields of the handshake messages. We then reveal that some fields do not have the ability. We discuss methods for improving the existing method based on these finding.