signature=44e6ad92ccd870c7476daa16766eb582,Identification of BitTorrent Traffic for High Speed Netwo...

Identification of BitTorrent Traffic for High Speed Network Using Packet Sampling and Application Signatures

Guo Zhenbin and Qiu Zhengding(Institute of Information Science,Beijing Jiaotong University,Beijing 100044)

It is very difficult to identify peer-to-peer(P2P)traffic in high speed network environment because well-known port numbers are no longer reliable and application signatures are not efficient enough.In this paper,a BitTorrent traffic identification method for high speed network using packet sampling and application signatures is presented.Models of false negatives and false positives are developed to analyze the effects of packet sampling probability and application signatures probability on accuracy.The method is implemented with Snort by developing a flow state differentiating preprocessor.The experiment results show that the efficiency and accuracy of the method are exciting and the method can be applied to high speed network.The low limit of processing efficiency is over 800 Mbps on a personal computer hardware platform.Assuming that the method is applied to processing packets,the false negatives rate is about 0.6% with 0.5 sampling probability,about 5.9% with 0.1 sampling probability,and about 10.5% with 0.05 sampling probability.Assuming that the method is applied to analyzing flows,the false negatives rate is about 0.06% with 0.5 sampling probability,about 0.33% with 0.1 sampling probability,and about 1.1% with 0.05 sampling probability.The method shows excellent false positives with no packet falsely identified.The experiment results also show that the false negatives and false positives models are very accurate.

CAJViewer7.0 supports all the CNKI file formats; AdobeReader only supports the PDF format.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值