作者: Dario Bonfiglio , Marco Mellia , Michela Meo , Dario Rossi , Paolo Tofanelli
关键词:
摘要: Skype is a very popular VoIP software which has recently attracted the attention of research community and network operators. Following closed source proprietary design, protocols algorithms are unknown. Moreover, strong encryption mechanisms adopted by Skype, making it difficult to even glimpse its presence from traffic aggregate. In this paper, we propose framework based on two complementary techniques reveal Skypetraffic in real time. The first approach, Pearson'sChi-Square test agnostic VoIP-related trafficcharacteristics, used detect Skype's fingerprint packet framing structure, exploiting randomness introduced at bit level process. Conversely, second approach stochastic characterization terms arrival rate length, as features decision process Naive Bayesian Classifiers.In order assess effectiveness above techniques, develop an off-line cross-checking heuristic deep-packet inspection flow correlation, interesting per se. This allows us quantify amount false negatives positives gathered means proposed approaches: results obtained measurements different networks show that technique effective identifying traffic. While both classifier commonly used, idea leveraging novel. We adopt identify traffic, but same methodology can be applied other classification problems well.