題名: | Application Behavior Analysis by Stateful Automata Mechanism |
作者: | Huang, Nen-Fu Feng, Yi-Hsuan |
關鍵字: | application classification stateful method |
摘要: | A sufficient visibility into the behaviors of network applications from the Internet traffic is essential to the content security, traffic management, and measurement. This paper presents a methodology to perform a reliable traffic classification and distinguish activities of specific applications. Our approach uses the flow-based state machine to model a given network application and its behaviors (even with the encryption) and combines the signature matching, protocol analysis, and statistical test in order to make use of the strength of the three approaches. We further discuss the system design and the implementation of our framework,including the detection heuristics and system details. These systems are already deployed at the borders of network environments of several enterprises and organizations. At last, we demonstrate the effectiveness of the approach by applying it to identify various applications and malicious traffic. This study on application behaviors shows that it is possible to allow the expected activities of programs but disallow others between the endpoint users. |
日期: | 2008-11-11T08:57:23Z |
分類: | Journal of Computers第18卷 |
文件中的檔案:
檔案 | 描述 | 大小 | 格式 | |
---|---|---|---|---|
JOC_18_4_2.pdf | 386.74 kB | Adobe PDF | 檢視/開啟 |
在 DSpace 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。