GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • IMF - IT-Incident Management & IT-Forensics
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • IMF - IT-Incident Management & IT-Forensics
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics
  • Dokumentanzeige

Network forensic of partial SSL/TLS encrypted traffic classification using clustering-algorithms

Autor(en):
Wu, Meng-Da [DBLP] ;
Wolthusen, Stephen D. [DBLP]
Zusammenfassung
Machine learning tools have long been used in network traffic analysis, but their application to the network forensics domain and ist specific issues has been limited thus far. We investigate the applicability of several common machine learning techniques to identify and classify partial encrypted traffic as may be encountered by forensic investigators confronted only with partial post-hoc traces. Is is highly desirable to identify the types of applications and endpoints using such tunnels to faciliate further forensic investigation. In this paper, we therefore examine several clustering algorithms, namely DBSCAN (Density-Based Spatial Clustering of Application with Noise), K-means, and EM (Expectation-Maximization) with regard to their ability to classify encrypted partial traffic using inter-arrival time and TCP lenght information chosen for its predictive significance. Our experiments demonstrate promising classifiction results.
  • Vollständige Referenz
  • BibTeX
Wu, M.-D. & Wolthusen, S. D., (2008). Network forensic of partial SSL/TLS encrypted traffic classification using clustering-algorithms. In: Göbel, O., Frings, S., Günther, D., Nedon, J. & Schadt, D. (Hrsg.), IMF 2008 – IT Incident Management & IT Forensics. Bonn: Gesellschaft für Informatik e.V.. (S. 157-172).
@inproceedings{mci/Wu2008,
author = {Wu, Meng-Da AND Wolthusen, Stephen D.},
title = {Network forensic of partial SSL/TLS encrypted traffic classification using clustering-algorithms},
booktitle = {IMF 2008 – IT Incident Management & IT Forensics},
year = {2008},
editor = {Göbel, Oliver AND Frings, Sandra AND Günther, Detlef AND Nedon, Jens AND Schadt, Dirk} ,
pages = { 157-172 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
gi-proc-140-012.pdf248.8Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-234-5
ISSN: 1617-5468
Datum: 2008
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P140 - IMF 2008 – IT-Incident Management & IT Forensics [15]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.