首页> 外文会议>IEEE International Workshop on Information Forensics and Security >Encrypted HTTP/2 Traffic Monitoring: Standing the Test of Time and Space
【24h】

Encrypted HTTP/2 Traffic Monitoring: Standing the Test of Time and Space

机译:加密HTTP / 2流量监控:站在时间和空间的考验

获取原文

摘要

Encrypted HTTP/2 (h2) has been worldwide adopted since its official release in 2015. The major services over Internet use it to protect the user privacy against traffic interception. However, under the guise of privacy, one can hide the abnormal or even illegal use of a service. It has been demonstrated that machine learning algorithms combined with a proper set of features are still able to identify the incriminated traffic even when it is encrypted with h2. However, it can also be used to track normal service use and so endanger privacy of Internet users. Independently of the final objective, it is extremely important for a security practitioner to understand the efficiency of such a technique and its limit. No existing research has been achieved to assess how generic is it to be directly applicable to any service or website and how long an acceptable accuracy can be maintained.This paper addresses these challenges by defining an experimental methodology applied on more than 3000 different websites and also over four months continuously. The results highlight that an off-the-shelf machine-learning method to classify h2 traffic is applicable to many websites but a weekly training may be needed to keep the model accurate.
机译:自2015年官方发布自2015年以来,加密了HTTP / 2(H2)已经通过了全球。互联网的主要服务使用它来保护用户隐私免受交通拦截。但是,在隐私的幌子下,人们可以隐藏异常甚至非法使用服务。已经证明,即使用H2加密,机器学习算法与适当的特征相结合的机器学习算法仍然能够识别有罪的流量。但是,它也可以用于跟踪正常的服务使用,因此危及Internet用户的隐私。独立于最终目标,安全从业者对理解这种技术的效率及其限制非常重要。没有实现现有的研究来评估将通用直接适用于任何服务或网站,以及可接受的准确性可以维持多长时间。本文通过定义应用于3000多个不同网站的实验方法,并提供了这些挑战超过四个月不断。结果突出显示了分类H2流量的现成机器学习方法适用于许多网站,但可能需要每周训练来保持模型准确。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号