Wake Forest University
Support Vector Machine Classification of Network Streams Using a Spectrum Kernel Encoding
Abstract
dc:description.abstractThe growth of computer networking has raised the profile of network management issues, and for those institutions (academic, private, and public) that require high-speed networks these issues have not only become more pressing, but also more challenging. In particular, performance and security management rely heavily on automated tools that must operate in real-time, but creating real-time tools can be a difficult problem that is only exacerbated by prevalence of high-speed networking. One important piece of these tools is the task of network stream classification, which allows for the application protocol of a stream to be identified. Traditional stream classification methods, however, are becoming less reliable, due to increased use of both non-standard ports and encryption algorithms. As such, this work proposes a novel method for network stream classification, relying on the Support Vector Machine (SVM) algorithm. Using only information available in the headers of TCP packets, the SVM creates temporal features – encoded using a spectrum kernel representation – and aggregate features for classification. Experimental results show that 6 protocols of interest are classified with over 99% accuracy. Also, 200, 000 streams can be classified in, on average, 148 seconds, with a strong promise of further speed increases due to parallelization.
Degree
thesis:*- Grantor dc:publisher
- Wake Forest University
- Year dc:date.issued
- 2009
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Karode, Andrew
Subjects
dc:subject × 1Rights
- Language dc:language.iso
- en_US
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/10339/14826
- OAI identifier oai:identifier
- oai:wakespace.lib.wfu.edu:10339/14826