Invention Grant
- Patent Title: Identification and classification of web traffic inside encrypted network tunnels
- Patent Title (中): 加密网络隧道内网络流量的识别和分类
-
Application No.: US14025098Application Date: 2013-09-12
-
Publication No.: US09100309B2Publication Date: 2015-08-04
- Inventor: Mihai Christodorescu , Xin Hu , Douglas L. Schales , Reiner Sailer , Marc Ph. Stoecklin , Ting Wang , Andrew M. White
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Tuntunjian & Bitetto, P.C.
- Agent Anne V. Dougherty
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/26 ; G06N5/02 ; G06N5/00 ; G06N99/00

Abstract:
The present principles are directed to identifying and classifying web traffic inside encrypted network tunnels. A method includes analyzing network traffic of unencrypted data packets to detect packet traffic, timing, and size patterns. The detected packet, timing, and size traffic patterns are correlated to at least a packet destination and a packet source of the unencrypted data packets to create at least one of a training corpus and a model built from the training corpus. The at least one of the corpus and model is stored in a memory device. Packet traffic, timing, and size patterns of encrypted data packets are observed. The observed packet traffic, timing, and size patterns of the encrypted data packets are compared to at least one of the training corpus and the model to classify the encrypted data packets with respect to at least one of a predicted network host and predicted path information.
Public/Granted literature
- US20140310517A1 IDENTIFICATION AND CLASSIFICATION OF WEB TRAFFIC INSIDE ENCRYPTED NETWORK TUNNELS Public/Granted day:2014-10-16
Information query