Semi-Supervised Fingerprinting of Protocol Messages - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Semi-Supervised Fingerprinting of Protocol Messages

Résumé

This paper addresses the fingerprinting of network devices using semi-supervised clustering. Semi-supervised clustering is a new technique that uses known and labeled data in order to assist a clustering process. We propose two different fingerprinting approaches. The first one is using behavioral features that are induced from a protocol state machine. The second one is relying on the underlying parse trees of messages. Both approaches are passive. We provide a performance analysis on the SIP protocol. Important application domains of our work consist in network intrusion detection and security assessment.
Fichier principal
Vignette du fichier
cisis10.pdf (175.98 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00536067 , version 1 (17-11-2010)

Identifiants

Citer

Jérôme François, Humberto Abdelnur, Radu State, Olivier Festor. Semi-Supervised Fingerprinting of Protocol Messages. CISIS 2010 - 3rd International Conference on Computational Intelligence in Security for Information Systems, Nov 2010, Léon, Spain. pp.107-115, ⟨10.1007/978-3-642-16626-6_12⟩. ⟨inria-00536067⟩
156 Consultations
241 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More