skip to main content
10.1145/1815396.1815568acmotherconferencesArticle/Chapter ViewAbstractPublication PagesiwcmcConference Proceedingsconference-collections
research-article

Entropy-based traffic filtering to support real-time Skype detection

Published:28 June 2010Publication History

ABSTRACT

We propose a novel approach for real-time privacy preserving traffic filtering based on entropy estimation. The decision of the real-time classifier is based on the entropy of the payload from first packet of a flow. The aim of the classifier is to detect traffic with encrypted payload. As a proof of concept we show the applicability of our approach as a traffic filter for a Skype detection engine. Traces collected in laboratory and real-world environments show that the traffic is reduced by a reasonable amount while achieving similar or even improved detection quality.

References

  1. D. Adami, C. Callegari, S. Giordano, M. Pagano, and T. Pepe. A real-time algorithm for skype traffic detection and classification. In NEW2AN, pages 168--179, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. A. Antos and I. Kontoyiannis. Convergence properties of functional estimates for discrete distributions. Random Structures and Algorithms, 19(3/4):163--193, 2001. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. D. Bonfiglio, M. Mellia, M. Meo, D. Rossi, and P. Tofanelli. Revealing skype traffic: when randomness plays with you. In SIGCOMM, pages 37--48, 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. D. Koukis, S. Antonatos, D. Antoniades, E. Markatos, and P. Trimintzios. A generic anonymization framework for network traffic. In Proceedings of the IEEE International Conference on Communications (ICC 2006), 2006.Google ScholarGoogle ScholarCross RefCross Ref
  5. J. Olivain and J. Goubault-Larrecq. Detecting subverted cryptographic protocols by entropy checking. Research Report LSV-06-13, Laboratoire Spécification et Vérification, ENS Cachan, France, June 2006.Google ScholarGoogle Scholar
  6. L. Paninski. Estimation of entropy and mutual information. Neural Computation, 15(6):1191--1253, 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. A. Pescape. Entropy-Based Reduction of Traffic Data. IEEE Communications Letters, 11(2):191, 2007.Google ScholarGoogle ScholarCross RefCross Ref

Index Terms

  1. Entropy-based traffic filtering to support real-time Skype detection

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Other conferences
          IWCMC '10: Proceedings of the 6th International Wireless Communications and Mobile Computing Conference
          June 2010
          1371 pages
          ISBN:9781450300629
          DOI:10.1145/1815396

          Copyright © 2010 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 28 June 2010

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • research-article

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader