• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2011, Vol. 33 ›› Issue (11): 10-14.

• 论文 • Previous Articles     Next Articles

A Method of Network Traffic Identification Based on Improved Clustering Algorithms

WANG Yuke1,LI Wenwei2,SU Xin2   

  1. (1.Center of Network Information,Hunan University,Changsha 410082;
    2.School of Information Science and Engineering,Hunan University,Changsha 410082,China)
  • Received:2011-06-03 Revised:2011-09-04 Online:2011-11-25 Published:2011-11-25

Abstract:

The automatic detection of applications associated with network traffic is very important for network security and traffic management. Unfortunately, because of some of the applications like P2P, VOIP applications using dynamic port numbers, masquerading techniques, and encryption, it is difficult using simple portbased analysis to classify packet payloads in order to identify these applications. And many research works have proposed using the clustering algorithms to identify network traffic, but these algorithms have some defects in how to choose the cluster center and the number of clusters. In this paper, we first use the Weighting D2 algorithm to improve the selection of the initialized cluster centers, and use the value of NMI(Normalize Mutual Information)to ascertain the number of clusters, and then get an improved clustering algorithm, and finally propose a application level identification method based on this algorithm. The experimental results show that this method  reaches 90% accuracy or more, and gets lower False Positive Rate and False Rejection Rate.

Key words: traffic identification;clustering algorithm;center of cluster;number of cluster