By Topic

On the Portability of Trained Machine Learning Classifiers for Early Application Identification

Sign In

Cookies must be enabled to login.After enabling cookies , please use refresh or reload or ctrl+f5 on the browser for the login options.

Formats Non-Member Member
$31 $13
Learn how you can qualify for the best price for this item!
Become an IEEE Member or Subscribe to
IEEE Xplore for exclusive pricing!
close button

puzzle piece

IEEE membership options for an individual and IEEE Xplore subscriptions for an organization offer the most affordable access to essential journal articles, conference papers, standards, eBooks, and eLearning courses.

Learn more about:

IEEE membership

IEEE Xplore subscriptions

1 Author(s)
Verticale, G. ; Dipt. di Elettron. e Inf., Politec. di Milano, Milan

The early identification of applications through the observation and fast analysis of the associated packet flows is a critical building block of intrusion detection and policy enforcement systems. The simple techniques currently used in practice, such as looking at the transport port numbers or at the application payload, are increasingly less effective for new applications using random port numbers and/or encryption.Therefore, there is increasing interest in machine learning techniques capable of identifying applications by examining features of the associated traffic process such as packet lengths and interarrival times. However, these techniques require that the classification algorithm is trained with examples of the traffic generated by the applications to be identified, possibly on the link where the classifier will operate.This is an important issue, as a pre-trained portable classifier would greatly facilitate the deployment and management of the classification infrastructure.The new contribution of this paper is a comparison of different sets of per-flow attributes that can be used for flow classification and the indication of which ones are more effective when the trained classifier is operated on a different link.

Published in:

Emerging Security Information, Systems and Technologies, 2008. SECURWARE '08. Second International Conference on

Date of Conference:

25-31 Aug. 2008