期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
DTA-HOC:Online HTTPS Traffic Service Identification Using DNS in Large-Scale Networks 被引量:2
1
作者 Xuemei Zeng Xingshu Chen +2 位作者 Guolin Shao Tao He Lina Wang 《Tsinghua Science and Technology》 SCIE EI CAS CSCD 2020年第2期239-254,共16页
An increasing number of websites are making use of HTTPS encryption to enhance security and privacy for their users.However,HTTPS encryption makes it very difficult to identify the service over HTTPS flows,which poses... An increasing number of websites are making use of HTTPS encryption to enhance security and privacy for their users.However,HTTPS encryption makes it very difficult to identify the service over HTTPS flows,which poses challenges to network security management.In this paper we present DTA-HOC,a novel DNS-based two-level association HTTPS traffic online service identification method for large-scale networks,which correlates HTTPS flows with DNS flows using big data stream processing and association technologies to label the service in an HTTPS flow with a specific associated domain name.DTA-HOC has been specifically designed to address three practical challenges in the service identification process:domain name ambiguity,domain name query invisibility,and data association time window size contradictions.Several experiments on datasets collected from a 10-Gbps campus network are conducted alongside offline and online testing.Results show that DTA-HOC can achieve an average online association rate on HTTPS traffic of 83%and a generic accuracy of 86.16%.Its processing time for one minute of data is less than 20 seconds.These results indicate that DTA-HOC is an efficient method for online identification of services in HTTPS flows for large-scale networks.Moreover,our proposed method can contribute to the identification of other applications which make a Domain Name System(DNS)communication before establishing a connection. 展开更多
关键词 HTTPS Domain Name System(DNS) service identification big data flow association
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部