SETA++: real-time scalable encrypted traffic analytics in multi-gbps networks

dc.date.accessioned2023-05-04T05:30:48Z
dc.date.available2023-05-04T05:30:48Z
dc.date.issued2021
dc.description.abstractThe security and privacy of the end-users are a few of the most important components of a communication network. Though end-to-end encryption (e.g., TLS/SSL) fulfils this requirement, it makes inspecting network traffic with legacy solutions such as Deep Packet Inspection difficult. Recent Machine Learning techniques have shown outstanding performance in encrypted traffic classification. Nevertheless, such approaches require efficient flow sampling at real enterprise-scale networks due to the sheer volume of transferred data. Through this paper, we propose a holistic architecture to extract flow information of encrypted data at multi Gbps line rate using sampling and sketching mechanisms, enabling network operators to estimate flow size distribution accurately and understand the behavior of VPN-obfuscated traffic. Using over 6000 video traffic traces, under three main evaluation scenarios based on trace duration and starting time point, we show that it is possible to achieve 99% accuracy for service provider classification and over 90% accuracy for content classification for a given service provider in the best case. We also deploy our solution at an operational enterprise-scale network leveraging kernel bypassing to demonstrate its capability to efficiently sample live traffic for analytics.en_US
dc.identifier.citationKattadige, C., Choi, K. N., Wijesinghe, A., Nama, A., Thilakarathna, K., Seneviratne, S., & Jourjon, G. (2021). SETA++: Real-time scalable encrypted traffic analytics in multi-gbps networks. IEEE transactions on network and service management, 18(3), 3244–3259. https://doi.org/10.1109/TNSM.2021.3085097en_US
dc.identifier.databaseIEE Xploreen_US
dc.identifier.doi10.1109/TNSM.2021.3085097en_US
dc.identifier.issn1932-4537en_US
dc.identifier.issue3en_US
dc.identifier.journalIEEE Transactions on Network and Service Managementen_US
dc.identifier.pgnos3244 - 3259en_US
dc.identifier.urihttp://dl.lib.uom.lk/handle/123/21002
dc.identifier.volume18en_US
dc.identifier.year2021en_US
dc.language.isoen_USen_US
dc.publisherIEEEen_US
dc.subjectEncrypted trafficen_US
dc.subjectflow samplingen_US
dc.subjectflow sketchingen_US
dc.subjectside-channel attacksen_US
dc.subjectnetwork measurementsen_US
dc.titleSETA++: real-time scalable encrypted traffic analytics in multi-gbps networksen_US
dc.typeArticle-Full-texten_US

Files