首页> 外文会议>Proceedings of the 1st Network Traffic Measurement and Analysis Conference >How HTTP/2 is changing web traffic and how to detect it
【24h】

How HTTP/2 is changing web traffic and how to detect it

机译:HTTP / 2如何改变网络流量以及如何检测到它

获取原文
获取原文并翻译 | 示例

摘要

HTTP constitutes a dominant part of the Internet traffic. Today's web traffic mostly consists of HTTP/1 and the much younger HTTP/2. As the traffic of both protocols is increasingly exchanged over encryption, discerning which flows in the network belong to each protocol is getting harder. Identifying flows per protocol is however very important, e.g., for building traffic models for simulations and benchmarking, and enabling operators and researchers to track the adoption of HTTP/2. This paper makes two contributions. First, using datasets of passive measurements collected in operational networks and Deep Packet Inspection (DPI), we characterize differences in HTTP/1 and HTTP/2 traffic. We show that the adoption of HTTP/2 among major providers is high and growing. Moreover, when comparing the same services over HTTP/1 or HTTP/2, we notice that HTTP/2 flows are longer, but formed by smaller packets. This is likely a consequence of new HTTP/2 features and the reorganization of servers and clients to profit from such features. Second, we present a lightweight method for the classification of encrypted web traffic into appropriate HTTP versions. In order to make the method practically feasible, we use machine learning with basic information commonly available in aggregated flow traces (e.g., NetFlow records). We show that a small labeled dataset is sufficient for training the system, and it accurately classifies traffic for several months, potentially from different measurement locations, without the need for retraining. Therefore, the method is simple, scalable, and applicable to scenarios where DPI is not possible.
机译:HTTP构成Internet流量的主要部分。当今的网络流量主要由HTTP / 1和更年轻的HTTP / 2组成。随着两种协议的流量越来越多地通过加密交换,越来越难辨别网络中属于每种协议的流量。然而,识别每个协议的流量非常重要,例如,对于建立用于仿真和基准测试的流量模型,以及使运营商和研究人员能够跟踪HTTP / 2的采用而言,这非常重要。本文有两个贡献。首先,我们使用在运营网络和深度数据包检查(DPI)中收集的被动测量数据集来表征HTTP / 1和HTTP / 2通信量的差异。我们表明,主要提供商之间对HTTP / 2的采用率很高并且还在不断增长。此外,当比较基于HTTP / 1或HTTP / 2的相同服务时,我们注意到HTTP / 2流更长,但由较小的数据包形成。这可能是新HTTP / 2功能以及服务器和客户端重组以从此类功能中获利的结果。其次,我们提出了一种轻量级的方法,用于将加密的网络流量分类为适当的HTTP版本。为了使该方法切实可行,我们将机器学习与聚合流迹中常见的基本信息(例如NetFlow记录)结合使用。我们显示了一个小的带标签的数据集足以训练系统,并且可以准确地对数月的流量进行分类(可能来自不同的测量位置),而无需重新训练。因此,该方法简单,可扩展,并且适用于不可能使用DPI的方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号