Volume 25, Issue 5 pp. 355-374
Research Article

A survey of methods for encrypted traffic classification and analysis

Petr Velan

Corresponding Author

Petr Velan

Institute of Computer Science, Masaryk University, Brno, Czech Republic

Correspondence to: Petr Velan, Institute of Computer Science, Masaryk University, Botanická 68a, Brno, Czech Republic.

E-mail: [email protected]

Search for more papers by this author
Milan Čermák

Milan Čermák

Institute of Computer Science, Masaryk University, Brno, Czech Republic

Search for more papers by this author
Pavel Čeleda

Pavel Čeleda

Institute of Computer Science, Masaryk University, Brno, Czech Republic

Search for more papers by this author
Martin Drašar

Martin Drašar

Institute of Computer Science, Masaryk University, Brno, Czech Republic

Search for more papers by this author
First published: 15 July 2015
Citations: 266

Summary

With the widespread use of encrypted data transport, network traffic encryption is becoming a standard nowadays. This presents a challenge for traffic measurement, especially for analysis and anomaly detection methods, which are dependent on the type of network traffic. In this paper, we survey existing approaches for classification and analysis of encrypted traffic. First, we describe the most widespread encryption protocols used throughout the Internet. We show that the initiation of an encrypted connection and the protocol structure give away much information for encrypted traffic classification and analysis. Then, we survey payload and feature-based classification methods for encrypted traffic and categorize them using an established taxonomy. The advantage of some of described classification methods is the ability to recognize the encrypted application protocol in addition to the encryption protocol. Finally, we make a comprehensive comparison of the surveyed feature-based classification methods and present their weaknesses and strengths. Copyright © 2015 John Wiley & Sons, Ltd.

The full text of this article hosted at iucr.org is unavailable due to technical difficulties.