|
TR-821-08
Towards Understanding Application Semantics of Network Traffic (thesis) |
|
| Authors: | Pang, Ruoming |
| Date: | May 2008 |
| Pages: | 176 |
| Download Formats: | [PDF] |
This dissertation explores the problem of building a semantic network traffic analysis system and using it to investigate various aspects of network traffic. Semantic traffic analysis uncovers the application-layer semantics conveyed in packets so that one can examine the specific requests, responses, status messages, error codes, and data items embedded in a connection dialog. Analyzing these at the application layer, as opposed to the syntactic byte-string layer, opens up much greater insight into the nature and context of the exchange between two hosts. For this reason, semantic traffic analysis is a cornerstone for precise network intrusion detection and also has broad applications in measurements of networking systems. |
|