Font Size: a A A

Research On Traffic Classification And Control Based On DPI And Incremental Decision Tree

Posted on:2014-01-12Degree:MasterType:Thesis
Country:ChinaCandidate:X QuFull Text:PDF
GTID:2268330422463430Subject:Information security
Abstract/Summary:PDF Full Text Request
With the rapid development of Internet technology, various types of streaming andP2P-based data transmission applications have sprung up, while greatly enriching people’sexperience of the network usage, they also occupy a great amount of network bandwidth.Analyzing the ingredient of the network traffic and controlling them respectively hasbecome a necessary work for efficient network usage.In this paper, the author deeply analysis four mainstream ways of network protocolidentification, including: port based method, packet content based method, flow featurebased method and hybrid flow identification method. The author further point out theshortcomings of existing studies on hybrid traffic classification models: Firstly,classification components in existing studies work as independent modules and are notworking together as a whole. Second, the impact of the fluctuation of bandwidth on flowfeatures has not been taken into consideration. Third, current studies use non-incrementalmachine learning algorithms to classify traffic, therefore cannot adapt to the latest changesof the flow features of protocols.Given this, the author firstly study the impact of the bandwidth fluctuation on flowfeatures and summarize some rules of choosing proper flow features in the field of trafficcontrol. An improved hybrid flow classification model based on DPI and flow featurebased method is proposed later. The model combines the advantages of the two methods,and can increase the accuracy by incremental learning. The author study the firewall andtraffic control tool of Linux, and then apply the proposed model to a real-time trafficcontrol system based on Linux platform. Tests verify the availability of the hybrid trafficclassification model and the traffic system archive expected design goal.
Keywords/Search Tags:Deep packet inspection, Incremental Decision Tree, Hybrid trafficclassification, Linux
PDF Full Text Request
Related items