发明名称 IDENTIFICATION AND CLASSIFICATION OF WEB TRAFFIC INSIDE ENCRYPTED NETWORK TUNNELS
摘要 The present principles are directed to identifying and classifying web traffic inside encrypted network tunnels. A method includes analyzing network traffic of unencrypted data packets to detect packet traffic, timing, and size patterns. The detected packet, timing, and size traffic patterns are correlated to at least a packet destination and a packet source of the unencrypted data packets to create at least one of a training corpus and a model built from the training corpus. The at least one of the corpus and model is stored in a memory device. Packet traffic, timing, and size patterns of encrypted data packets are observed. The observed packet traffic, timing, and size patterns of the encrypted data packets are compared to at least one of the training corpus and the model to classify the encrypted data packets with respect to at least one of a predicted network host and predicted path information.
申请公布号 US2015295805(A1) 申请公布日期 2015.10.15
申请号 US201514752139 申请日期 2015.06.26
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 CHRISTODORESCU MIHAI;HU XIN;SCHALES DOUGLAS L.;SAILER REINER;STOECKLIN MARC PH.;WANG TING;WHITE ANDREW M.
分类号 H04L12/26;H04L12/24;G06N99/00;H04L29/06;G06N5/02 主分类号 H04L12/26
代理机构 代理人
主权项 1. A system, comprising: a modeling engine for correlating detected packet traffic patterns, detected packet timing patterns, and detected packet size patterns of unencrypted data packets to at least a packet destination and a packet source of the unencrypted data packets to create at least one of a training corpus and a model built from the training corpus; and a memory for storing the at least one of the training corpus and the model, wherein the system further comprises a prediction engine for comparing observed packet traffic patterns, observed packet timing patterns, and observed packet size patterns of encrypted data packets to at least one of the training corpus and the model to classify the encrypted data packets with respect to at least one of a predicted network host and predicted path information for the encrypted data packets.
地址 Armonk NY US