Detail publikace

Traffic Extraction and Classification in Network Forensics

PLUSKAL, J.; RYŠAVÝ, O. Traffic Extraction and Classification in Network Forensics. 9th International Conference on Digital Forensics & Cyber Crime. Praha: 2017. p. 1-2.
Typ
článek ve sborníku konference
Jazyk
anglicky
Autoři
Klíčová slova

network forensics network traffic classification statistical protocol identification

Abstrakt

Network traffic classification is essential for network monitoring, security analysis and also digital forensics. Accurate classification can reduce the amount of information that needs to be analyzed during the investigation. In this paper, we present a study that compares three different algorithms that according to the literature oer high accuracy and acceptable performance. These algorithms are evaluated on their ability to identify traffic classes at application protocol and also network application software levels. Based on experiments, Random forest algorithm gives promising results.

Rok
2017
Strany
1–2
Sborník
9th International Conference on Digital Forensics & Cyber Crime
Místo
Praha
BibTeX
@inproceedings{BUT168456,
  author="Jan {Pluskal} and Ondřej {Ryšavý}",
  title="Traffic Extraction and Classification in Network Forensics",
  booktitle="9th International Conference on Digital Forensics & Cyber Crime",
  year="2017",
  pages="1--2",
  address="Praha",
  url="https://www.fit.vut.cz/research/publication/11457/"
}
Nahoru