Passive measurement method for unknown network protocol identification and classification

Network traffic monitoring is a way for enterprises to meet performance, security and compliance goals. Yet implementing network traffic monitoring tools can also pose a series of challenges that range from difficulty in identifying exact network traffic to trouble finding the right tools and strate...

Full description

Saved in:
Bibliographic Details
Main Author: Norayu, Abd Ghani
Format: Thesis
Language:English
English
Published: 2010
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/15484/1/Passive%20measurement%20method%20for%20unknown%20network%20protocol%20identification%20and%20classification.pdf
http://eprints.utem.edu.my/id/eprint/15484/2/Passive%20measurement%20method%20for%20unknown%20network%20protocol%20identification%20and%20classification.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Network traffic monitoring is a way for enterprises to meet performance, security and compliance goals. Yet implementing network traffic monitoring tools can also pose a series of challenges that range from difficulty in identifying exact network traffic to trouble finding the right tools and strategies for monitoring. Software protocol analyzer is a popular tool in helping network administrator to perform network traffic monitoring. In view of the fact that, accuracy in identification and classification of network packet could advanced network monitoring, and better understanding of the operational networks applications. Therefore, every packets running on the network should be able to be recognized and accurately defined to optimize network resources· usage and return of investment. Anyhow, the capability of network protocol analyzer in decoding network traffic could be a challenge to the network administrator. Capturing network traffic with unknown network protocol is a challenge to provide efficient and accurate network service. This work is focusing on to identify and reclassify the unknown network protocol in UTeM network. UNTICED methodology proposed in this research able to accurately identify and reclassify unknown network protocol in the university network. While many software protocol anal y~er vendor claims to provide accurate protocol classification, research finding confirms that different software protocol analyzer classified protocol differently. For this reason the accuracy of network protocol analyzer claimed is to confirm tool dependent.