| 講演抄録/キーワード |
| 講演名 |
2009-03-13 17:05
暗号化・平文トラヒックの差分分析とその特徴にもとづく暗号化トラヒック検出法 ○南浦優樹・阿多信吾(阪市大)・中村信之・中平佳裕(OKI)・村田正幸(阪大)・岡 育生(阪市大) ICM2008-89 |
| 抄録 |
(和) |
ネットワーク管理においてトラヒック種別を識別することは非常に重要であるが、近年暗号化トラヒックの増加により、その識別が容易ではなくなりつつある。暗号化されたトラヒックの内容からアプリケーションを識別することは一般的に困難であり、暗号化トラヒックの増加によって、これまでのアプリケーション識別技術が正確に動作しないことが考えられる。このような場合、トラヒックが暗号化されているかどうかを検出し、暗号化されている場合は暗号化オーバーヘッド等を除去したトラヒックで識別を実施することが望ましい。本稿では、このような暗号化トラヒックをより早期に検出するための手法について検討する。具体的にはトラヒック特性を示す多種の統計情報について、暗号化トラヒックと平文トラヒック間の差分を分析する。そして、差分がより顕著となる統計値が何かを明らかにし、その統計値を用いた新しい暗号化トラヒック検出法を提案する。 |
| (英) |
In network management, identification of traffic type is important. However encrypted traffic has been increasing (in recent year), and so it is becoming difficult to identify the traffic type. The identification of application from the encrypted traffic is generally difficult, and so it is expected that existing method to identify the application can’t operate accurately. One of method to overcome this problem is to detect whether traffic is encrypted or not, and identification is operated for traffic remove encryption overhead from encrypted traffic. In this paper, we study the method to detect encrypted traffic early. We analyze statistical information of encrypted traffic and plaintext traffic. We show statistical information which has remarkable characteristics in each traffic.We then propose the method to detect encrypted traffic by using the information. |
| キーワード |
(和) |
トラヒック識別 / 暗号化 / 統計情報 / パケット到着間隔 / ネットワーク計測 / / / |
| (英) |
traffic Identification / encryption / statistical information / packet inter-arrival time / network measurement / / / |
| 文献情報 |
信学技報, vol. 108, no. 481, ICM2008-89, pp. 179-184, 2009年3月. |
| 資料番号 |
ICM2008-89 |
| 発行日 |
2009-03-05 (ICM) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICM2008-89 |