Wake Forest University
Identifying Application Protocols in Computer Networks Using Vertex Profiles
Abstract
dc:description.abstractSecurity and management of computer network resources exemplify two critical activities that challenge system administrators. They face potential threats from outside intruders as well as internal users whom already have access to the organization’s assets. It is imperative that administrators are aware of what applications are being executed, but the use of data encryption techniques and non-standard port numbers presents difficulties that must be overcome. To that end, this thesis introduces a novel method to identify application protocols based on the analysis of application graphs, which model application-level communications between computers. The performance of two types of node descriptions, called vertex profiles, are compared. “Traditional” vertex profiles characterize each node using several well-studied graph measures. Furthermore, this work uniquely applies motif-based analysis, which has previously been used primarily in systems biology, to the study of application graphs by creating a second type of vertex profile based on a node’s participation in statistically significant motifs. Machine learning techniques are employed to evaluate the importance of specific profile features. The experimental results, using a nearest-neighbor classifier, show that this type of analysis can correctly classify the applications observed with greater than 80% accuracy.
Degree
thesis:*- Grantor dc:publisher
- Wake Forest University
- Year dc:date.issued
- 2008
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Allan, Edward Jr
Subjects
dc:subject × 1Rights
- Language dc:language.iso
- en_US
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/10339/14755
- OAI identifier oai:identifier
- oai:wakespace.lib.wfu.edu:10339/14755