透過您的圖書館登入
IP:3.145.91.37
  • 期刊

Application Behavior Analysis by Stateful Automata Mechanism

並列摘要


A sufficient visibility into the behaviors of network applications from the Internet traffic is essential to the content security, traffic management, and measurement. This paper presents a methodology to perform a reliable traffic classification and distinguish activities of specific applications. Our approach uses the flow-based state machine to model a given network application and its behaviors (even with the encryption) and combines the signature matching, protocol analysis, and statistical test in order to make use of the strength of the three approaches. We further discuss the system design and the implementation of our framework, including the detection heuristics and system details. These systems are already deployed at the borders of network environments of several enterprises and organizations. At last, we demonstrate the effectiveness of the approach by applying it to identify various applications and malicious traffic. This study on application behaviors shows that it is possible to allow the expected activities of programs but disallow others between the endpoint users.

被引用紀錄


Kao, C. N. (2015). 新一代嵌入式網路安全系統 [doctoral dissertation, National Tsing Hua University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0016-0312201510305235

延伸閱讀