Authors:
Jawad Khalife
1
;
Amjad Hajjar
1
and
Jesús Díaz-Verdejo
2
Affiliations:
1
Lebanese University, Lebanon
;
2
University of Granada, Spain
Keyword(s):
Network traffic identification, Deep packet inspection, Payload truncation.
Related
Ontology
Subjects/Areas/Topics:
Data Communication Networking
;
Network Monitoring and Control
;
Network Protocols
;
Telecommunications
;
Traffic Measurement, Analysis, Modeling and Visualization
Abstract:
The identification of the nature of the traffic flowing through a TCP/IP network is a relevant target for traffic engineering and security related tasks. Traditional methods based on port assignments are no longer valid due to the use of ephemeral ports and ciphering. Despite the privacy concerns it arises, Deep Packet Inspection (DPI) is one of the most successful current techniques. Nevertheless, the performance of DPI is strongly limited by computational issues related to the huge amount of data it needs to handle, both in terms of number of packets and the length of the packets. This paper addresses the sensitivity of OpenDPI, one of the most powerful freely available DPI systems, when truncation of the payloads of the monitored traffic is applied. The results show that it is highly dependent on the protocol being monitored.