Results 1 to 2 of 2

Thread: 'Tunnel Hunter' Detects Encrypted P2P Traffic With 90% Accuracy

  1. #1
    Jorge's Avatar

    Zeropaid God

    Join Date
    Mar 2000
    Location
    San Diego, CA
    Posts
    3,309

    Post 'Tunnel Hunter' Detects Encrypted P2P Traffic With 90% Accuracy

    Italian researchers say they can detect SSH tunnels with 99% accuracy and actual protocol (P2P, POP3, SMTP, HTTP) with 90% accuracy.
    Italian Researchers at the Universita degli Studidi Brescia (University of Brescia Studies?) have developed a statistical method called "Tunnel Hunter" for detecting encrypted tunneling activities with 99% accuracy.
    Using a naive Bayes approach to previously classify different protocols such as P2P, POP3, SMTP, and HTTP, they have used the same basic classification algorithm to detect SSH tunnels. Instead of using Deep Packet Inspection (DPI) they analyze three simple properties of IP packets: their size, inter-arrival time and arrival order.
    The main theory they argue is that that a fingerprint can be derived by training the system on legitimate, non-tunneling SSH usage, and then later be used to detect application-layer tunnels that are run on top of a Secure Shell.



    Read Full Article Here

  2. #2
    Mels_Smileys45's Avatar

    JabberZombie

    Join Date
    Dec 2003
    Location
    Forman's Basement
    Posts
    16,236
    Where is The Hunter anyways?




    Hard as ever and here to make you people believe...as long as there is one person to hold hope and dream...A GOD...will never die!

Similar Threads

  1. Looking to Block P2P Traffic?
    By g-smooth2k in forum News
    Replies: 6
    Last Post: July 29th, 2008, 09:24 AM
  2. Identifying P2P users using traffic analysis
    By mp3master1215 in forum News
    Replies: 18
    Last Post: January 1st, 2006, 10:25 AM
  3. In praise of P2P
    By g-smooth2k in forum News
    Replies: 0
    Last Post: December 7th, 2004, 01:44 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •