{"id":{"repo_id":"wfu","oai_identifier":"oai:wakespace.lib.wfu.edu:10339/14826"},"canonical_url":"https://search.dev.ndltd.org/etd/wfu/oai:wakespace.lib.wfu.edu:10339/14826","repository":{"repo_id":"wfu","name":"Wake Forest University","base_url":"https://wakespace.lib.wfu.edu/oai/request"},"display":{"title":"Support Vector Machine Classification of Network Streams Using a Spectrum Kernel Encoding","abstract":"The growth of computer networking has raised the profile of network management issues, and for those institutions (academic, private, and public) that require high-speed networks these issues have not only become more pressing, but also more challenging. In particular, performance and security management rely heavily on automated tools that must operate in real-time, but creating real-time tools can be a difficult problem that is only exacerbated by prevalence of high-speed networking. One important piece of these tools is the task of network stream classification, which allows for the application protocol of a stream to be identified. Traditional stream classification methods, however, are becoming less reliable, due to increased use of both non-standard ports and encryption algorithms. As such, this work proposes a novel method for network stream classification, relying on the Support Vector Machine (SVM) algorithm. Using only information available in the headers of TCP packets, the SVM creates temporal features – encoded using a spectrum kernel representation – and aggregate features for classification. Experimental results show that 6 protocols of interest are classified with over 99% accuracy. Also, 200, 000 streams can be classified in, on average, 148 seconds, with a strong promise of further speed increases due to parallelization.","abstract_html":"The growth of computer networking has raised the profile of network management issues, and for those institutions (academic, private, and public) that require high-speed networks these issues have not only become more pressing, but also more challenging. In particular, performance and security management rely heavily on automated tools that must operate in real-time, but creating real-time tools can be a difficult problem that is only exacerbated by prevalence of high-speed networking. One important piece of these tools is the task of network stream classification, which allows for the application protocol of a stream to be identified. Traditional stream classification methods, however, are becoming less reliable, due to increased use of both non-standard ports and encryption algorithms. As such, this work proposes a novel method for network stream classification, relying on the Support Vector Machine (SVM) algorithm. Using only information available in the headers of TCP packets, the SVM creates temporal features – encoded using a spectrum kernel representation – and aggregate features for classification. Experimental results show that 6 protocols of interest are classified with over 99% accuracy. Also, 200, 000 streams can be classified in, on average, 148 seconds, with a strong promise of further speed increases due to parallelization.","abstract_has_math":false,"creators":["Karode, Andrew"],"institution":"Wake Forest University","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2009,"date_issued":"2009-01-27T19:21:53Z","date_published":"2009-01-27T19:21:53Z","updated_at":"2026-07-27T22:01:01Z","subjects":["spectrum kernel"],"languages":["en_US"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/10339/14826","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Karode, Andrew"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2009-01-27T19:21:53Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2009-01-27T19:21:53Z"]},{"key":"dc:date.issued","label":"Date","values":["2009-01-27T19:21:53Z"]},{"key":"dc:publisher","label":"Institution","values":["Wake Forest University"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["spectrum kernel"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en_US"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/10339/14826"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The growth of computer networking has raised the profile of network management issues, and for those institutions (academic, private, and public) that require high-speed networks these issues have not only become more pressing, but also more challenging. In particular, performance and security management rely heavily on automated tools that must operate in real-time, but creating real-time tools can be a difficult problem that is only exacerbated by prevalence of high-speed networking. One important piece of these tools is the task of network stream classification, which allows for the application protocol of a stream to be identified. Traditional stream classification methods, however, are becoming less reliable, due to increased use of both non-standard ports and encryption algorithms. As such, this work proposes a novel method for network stream classification, relying on the Support Vector Machine (SVM) algorithm. Using only information available in the headers of TCP packets, the SVM creates temporal features – encoded using a spectrum kernel representation – and aggregate features for classification. Experimental results show that 6 protocols of interest are classified with over 99% accuracy. Also, 200, 000 streams can be classified in, on average, 148 seconds, with a strong promise of further speed increases due to parallelization."]},{"key":"dc:title","label":"Title","values":["Support Vector Machine Classification of Network Streams Using a Spectrum Kernel Encoding"]}]}],"canonical_facts":{"dc:creator":["Karode, Andrew"],"dc:date.accessioned":["2009-01-27T19:21:53Z"],"dc:date.available":["2009-01-27T19:21:53Z"],"dc:date.issued":["2009-01-27T19:21:53Z"],"dc:description.abstract":["The growth of computer networking has raised the profile of network management issues, and for those institutions (academic, private, and public) that require high-speed networks these issues have not only become more pressing, but also more challenging. In particular, performance and security management rely heavily on automated tools that must operate in real-time, but creating real-time tools can be a difficult problem that is only exacerbated by prevalence of high-speed networking. One important piece of these tools is the task of network stream classification, which allows for the application protocol of a stream to be identified. Traditional stream classification methods, however, are becoming less reliable, due to increased use of both non-standard ports and encryption algorithms. As such, this work proposes a novel method for network stream classification, relying on the Support Vector Machine (SVM) algorithm. Using only information available in the headers of TCP packets, the SVM creates temporal features – encoded using a spectrum kernel representation – and aggregate features for classification. Experimental results show that 6 protocols of interest are classified with over 99% accuracy. Also, 200, 000 streams can be classified in, on average, 148 seconds, with a strong promise of further speed increases due to parallelization."],"dc:identifier.uri":["http://hdl.handle.net/10339/14826"],"dc:language.iso":["en_US"],"dc:publisher":["Wake Forest University"],"dc:subject":["spectrum kernel"],"dc:title":["Support Vector Machine Classification of Network Streams Using a Spectrum Kernel Encoding"],"dc:type":["Thesis"]},"updated_at":"2026-07-27T22:01:01Z"}