With the growing use of protocols obfuscation techniques, protocol identification for Q.O.S enforcement,traffic prohibition, and intrusion detection has became a complex task. This paper addresses this issue with a probabilistic identification analysis that combines multiples advanced identification techniques and returns an ordered list of probable protocols. It combines a payload analysis with a classifier based on several discriminators, including packet entropy and size. We show with its implementation, that it overcomes the limitations of traditional port-based protocol identification when dealing with hard to classify protocol such as peer to peer protocols. We also detail how it deals with tunneled session and covert channel.
Probabilistic protocol identification for hard to classify protocol
| Available Media | |
|---|---|
| Conference | 2nd International Workshop on Information Security Theory and Practices (WISTP) - 2008 |
| Author | Elie Bursztein |
| Award | Best Paper Award |
| Citation | BibTeX |
Recent
ai
Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection
publications
Usenix Security 2026
ai
ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?
publications
NeurIPS 2026
Cybersecurity
DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement
publications
ACSAC 2025