skip to main content
research-article

GT: picking up the truth from the ground for internet traffic

Published:07 October 2009Publication History
Skip Abstract Section

Abstract

Much of Internet traffic modeling, firewall, and intrusion detection research requires traces where some ground truth regarding application and protocol is associated with each packet or flow. This paper presents the design, development and experimental evaluation of gt, an open source software toolset for associating ground truth information with Internet traffic traces. By probing the monitored host's kernel to obtain information on active Internet sessions, gt gathers ground truth at the application level. Preliminary experimental results show that gt's effectiveness comes at little cost in terms of overhead on the hosting machines. Furthermore, when coupled with other packet inspection mechanisms, gt can derive ground truth not only in terms of applications (e.g., e-mail), but also in terms of protocols (e.g., SMTP vs. POP3).

References

  1. The Ground Truth software tools. http://www.ing.unibs.it/ntw/tools/gt.Google ScholarGoogle Scholar
  2. J. Erman, M. Arlitt, and A. Mahanti. Traffic classification using clustering algorithms. In Proc. ACM SIGCOMM MINENET Workshop, Pisa, Italy, Sep. 2006. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. H. Kim, K. Claffy, M. Fomenkova, D. Barman, and M. Faloutsos. Internet Traffic Classification Demystified: The Myths, Caveats and Best Practices. In Proc. ACM CoNEXT, Madrid, Spain, Dec. 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. The Cooperative Association for Internet Data Analysis (CAIDA). http://www.caida.org.Google ScholarGoogle Scholar
  5. LBNL/ICSI Enterprise Tracing Project. http://www.icir.org/enterprise-tracing.Google ScholarGoogle Scholar
  6. M. Dusi, M. Crotti, F. Gringoli, and L. Salgarelli. Tunnel hunter: Detecting application-layer tunnels with statistical fingerprinting. Elsevier Computer Netw., 53(1):81--97, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. I. Trestian, S. Ranjan, A. Kuzmanovi, and A. Nucci. Unconstrained endpoint profiling (googling the Internet). SIGCOMM Comput. Commun. Rev., 38(4):279--290, 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. T. Karagiannis, K. Papagiannaki, and M. Faloutsos. BLINC: multilevel traffic classification in the dark. In Proc. ACM SIGCOMM, Philadelphia, PA, USA, Aug. 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. G. Szabo, D. Orincsay, S. Malomsoky, and I. Szabo. On the Validation of Traffic Classification Algorithms. In Proc. PAM2008, Cleveland, OH, USA, Apr. 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. M. Canini, W. Li, A.W. Moore, and R. Bolla. GTVS: Boosting the Collection of Application Traffic Ground Truth. In Proc. 1st Intl. Workshop on Traffic Monitoring and Analysis, Aachen, Germany, May 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. L7 Filter. http://l7-filter.sourceforge.net.Google ScholarGoogle Scholar
  12. Tcpdump/Libpcap. http://www.tcpdump.org.Google ScholarGoogle Scholar
  13. M. Baldi, A. Baldini, N. Cascarano, and F. Risso. Service-based traffic classification: Principles and validation. In Proc. IEEE 2009 Sarnoff Symposium, Princeton, NJ, USA, Mar. 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. P. Biondi and F. Desclaux. Silver Needle in the Skype. In BlackHat Europe, Amsterdam, The Netherlands, Mar. 2006.Google ScholarGoogle Scholar

Index Terms

  1. GT: picking up the truth from the ground for internet traffic

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in

    Full Access

    • Published in

      cover image ACM SIGCOMM Computer Communication Review
      ACM SIGCOMM Computer Communication Review  Volume 39, Issue 5
      October 2009
      49 pages
      ISSN:0146-4833
      DOI:10.1145/1629607
      Issue’s Table of Contents

      Copyright © 2009 Authors

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 7 October 2009

      Check for updates

      Qualifiers

      • research-article

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader